Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

42 results about "Kill chain" patented technology

The term kill chain was originally used as a military concept related to the structure of an attack; consisting of target identification, force dispatch to target, decision and order to attack the target, and finally the destruction of the target. Conversely, the idea of "breaking" an opponent's kill chain is a method of defense or preemptive action. More recently, Lockheed Martin adapted this concept to information security, using it as a method for modeling intrusions on a computer network. The cyber kill chain model has seen some adoption in the information security community. However, acceptance is not universal, with critics pointing to what they believe are fundamental flaws in the model.

Method and device for constructing and recommending equipment system adversarial network of dynamic time sequence event

The invention discloses a dynamic time sequence event equipment system adversarial network construction and recommendation method and device, and relates to the field of killing network design, and the method comprises the steps: constructing an initial detection-command and control-strike warning network; a dynamic time sequence event on the battlefield is continuously monitored, when the event type of the dynamic time sequence event is an equipment state event, the initial detection-command-strike warning network is updated, and when the event type of the dynamic time sequence event is a chained event, a closed detection-command-strike link set containing an enemy target is generated; the closed detection-command-strike link set comprises a plurality of killing chains; based on the multi-dimensional evaluation index system, evaluating each killing chain to obtain an evaluation result corresponding to each killing chain; and according to the evaluation results corresponding to all the killing chains, recommending an optimal interception scheme of an air defense and anti-guide interception action. The method overcomes the problems of large calculation dimension and slow response speed of an existing method.
Owner:BEIJING INST OF TECH

Security event tracing system and method based on attack chain analysis

The invention discloses a security event traceability system and method based on attack chain analysis, relates to the technical field of data security protection, and is used for realizing multi-level perception of attack activities by building a multi-modal killing chain probe matrix as a structured data basis. Modeling analysis is carried out on attack behaviors of different levels through a deep heterogeneous feature extraction architecture, multi-dimensional features are fused into a cross-layer joint feature vector, a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector, the propagation path and probability of APT attack are simulated, a high-dimensional attack curved surface is drawn, and a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector. And key path nodes and potential transverse diffusion directions are identified, and a defense strategy knowledge graph is constructed according to a modeling result. The traceability system breaks through barriers among threat detection, attack understanding and defense response through a stage linkage mode of'probe sensing-intention recognition-path modeling-defense deduction ', and realizes accurate traceability and efficient disposal of security events.
Owner:SHANGRAO DAWAN NETWORK TECHNOLOGY CO LTD

Service-based killer chain analysis construction method

The invention discloses a service-based killer chain analysis construction method, which belongs to the technical field of cooperative combat, and comprises the following steps: constructing a service resource pool, and setting a service discovery mechanism; on the basis of the fusion situation set, a situation switching event is recognized so as to perform local updating, and a three-level situation view is constructed; constructing a directed hyperedge, generating a directed hypergraph in combination with function category constraints, generating a dimensionality reduction state space based on multi-dimensional constraints, and generating an initial combat candidate set; configuring a management node, sending task invitation information to the initial combat candidate set in combination with the subtasks, generating a response scheme, performing adaptive screening, generating an initial killing chain, and performing failure verification; constructing a servitization twinborn body, deducing the initial killing chain, and executing delay at a calculation end so as to perform elimination recombination or delay optimization; a service combination template is constructed, an efficiency feedback mechanism is established, the superposition influence of frequent situation switching and state space catastrophe is cooperatively solved, and the real-time performance of generation of the killing chain is remarkably improved.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Multi-scale fusion network performance evaluation method based on killer chain driving

The invention discloses a multi-scale fusion network efficiency evaluation method based on killing chain driving, and the method employs the bottom-up idea of a complex system, considers the three-in-one condition of confrontation, dynamic and overall structure based on the incidence relation of nodes, a killing chain and a killing network, and carries out the evaluation of the efficiency of a multi-scale fusion network. An evaluation model from a micro scale to a middle scale and then to a macro scale is constructed, and the feasibility of the method is verified by comparing network efficiencies of tactical-level command systems with different architecture forms through simulation. By using the method, the integrality, the dynamic nature, the antagonism and the uncertainty characteristics of the network are comprehensively considered, and efficiency evaluation can be performed on the network in different environments. The method can be widely applied to the field of network performance evaluation.
Owner:SUN YAT SEN UNIV

Unmanned aerial vehicle cluster survivability evaluation method based on killing chain

The invention discloses an unmanned aerial vehicle cluster survivability evaluation method based on a killing chain, and relates to the technical field of unmanned combat system evaluation, and the method comprises the following steps: S1, summarizing the types and number of our unmanned aerial vehicles, forming a our unmanned aerial vehicle equipment list, and collecting enemy target information, and forming an enemy target list; s2, according to the communication relationship between the unmanned aerial vehicle clusters, analyzing the network topology structure of the unmanned aerial vehicle cluster combat, eliminating invalid network communication modes and enemy target nodes, and forming a directed unmanned aerial vehicle cluster survivability analysis network graph D = lt; e, Vgt; . According to the unmanned aerial vehicle cluster survivability evaluation method based on the killing chain, different unmanned aerial vehicle nodes are destroyed, the comprehensive survivability evaluation value change of the whole unmanned aerial vehicle cluster is calculated, a survivability change trend chart is drawn, and key equipment nodes and weak links which have the largest influence on network survivability are judged.
Owner:CHINA ORDNANCE SCI INST

Cps attack path reconstruction method and system based on kill chain model clustering

The application belongs to the technical field of network security, and particularly relates to a CPS attack path reconstruction method and system based on a kill chain model clustering. CPS information layer and physical layer operation data are collected, a feature vector is generated through time window fusion, a feature subspace is divided based on the four stages of the kill chain, candidate clusters are obtained by clustering the data of each stage, high-confidence clusters are screened in combination with time concentration and behavior intensity, a causal diagram is constructed according to time proximity and cross-layer correlation, and complete reconstruction of the attack path is realized; the application adapts to the cross-layer coupling characteristics of CPS, improves the accuracy of attack stage division and path reconstruction, and can provide reliable support for attack tracing and defense strategy formulation.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Asset remediation trend map generation and utilization for threat mitigation

The present disclosure relates to methods, systems, and computer program products for generating an asset remediation trend map used in remediating against an attack campaign. The method comprises receiving attack kill chain data. The attack kill chain data comprises steps for executing an attack campaign on one or more assets associated with a computing device. The method further comprises parsing the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device. The method determines based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations. In addition, the method sequences the one or more remediation operations to form an asset remediation trend map. In one implementation, the asset remediation trend map indicates steps for remediating the attack campaign.
Owner:QUALYS

Threat activity statistical analysis driven adaptation of a control specification

Threat activity statistical analysis driven adaptive control specification includes retrieving a data structure from over a computer communications network into memory of a computing device and parsing the data structure in the memory to extract a listing of different threat activities. Threat activity statistical analysis driven adaptive control specification also includes computing in the memory a statistical analysis of the different threat activities. Finally, threat activity statistical analysis driven adaptive control specification includes responding to the statistical analysis surpassing a threshold for an identified one of the different threat activities by determining a corresponding threat incorporating the identified one of the different threat activities in an associated kill chain, retrieving a control specification addressing the corresponding threat, and modifying the control specification to address changes in the corresponding threat.
Owner:HITRUST SERVICES LLC

A service-based kill chain analysis construction method

The application discloses a kind of service-based kill chain analysis construction methods, belong to the technical field of cooperative combat, including: constructing service resource pool, and set service discovery mechanism;Based on fusion situation set, identify situation switching event, to carry out local update, and construct three-level situation view;Directed hyperedge is constructed, combined with function category constraint, generates directed hypergraph, generates dimensionality reduction state space based on multidimensional constraint, and generates initial combat candidate set;Configuration management node, combined with subtask to the initial combat candidate set sends task invitation information, generates response scheme and carries out adaptation screening, generates initial kill chain, and carries out failure check;Build service twin, deduce the initial kill chain, calculate end execution delay, to carry out elimination reorganization or delay optimization;Build service combination template, and establish efficiency feedback mechanism, cooperatively solve the superimposed influence of frequent situation switching and state space catastrophe, significantly improve kill chain generation real-time performance.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Detection of multi-killchain alerts

A method for the detection of multi-killchain alerts is disclosed. The method includes receiving, by a computer system, a plurality of alerts indicative of activity within a computer network, wherein a given alert specifies one or more events having attributes, and extracting attributes from events included in the plurality of alerts. The method further includes determining attribute similarity for pairs of events based on whether a given pair of events has common values for one or more attributes and whether attribute values of the given pair of events indicates lateral movement within computers of the computer network. Linked pairs are then identified based on the determined attribute similarity and added to a graph data structure. The method further includes the computer system analyzing the graph data structure to find clusters of events relating to a security attack.
Owner:SALESFORCE INC

Context-aware security policies and incident identification via automated cloud graph building with security overlays

Context-aware security policies and incident identification, via automated cloud graph building with security overlays, are determined and performed by systems and platforms. Graph nodes, of a graph associated with a computing system, that represent resources associated with the computing system and entities associated with the computing system that have respective associations to the resources are generated. Security attributes are determined and assigned to the graph nodes that represent the entities and resources, and static and dynamic connections between the graph nodes are added to the graph. Additionally, possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes. From the graph, security incidents and kill chains are identified, context-aware security policies are generated and validated, and scopes and relationships of applications are identified. Accordingly, security actions are taken for the computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method for quickly and dynamically reconstructing ultra-long-distance air-to-air killer chain

The invention discloses a method for quickly and dynamically reconstructing an ultra-long-distance air-to-air killing chain, belongs to the technical field of ultra-long-distance air-to-air killing chains, and realizes dynamic recombination of the killing chain by using a self-organizing iterative clustering algorithm. In the execution process of the killing chain, if a reconstruction condition is triggered, all the combat platforms in normal operation are divided into six clusters according to the execution stages of discovery, positioning, tracking, aiming, combat and evaluation, each cluster is divided into different groups according to different loads loaded by the combat platforms, and the loading loads comprise ESM, light thunder and radar; for the combat platforms loaded with the same load, dividing the combat platforms in the same area into the same cluster by taking the current position as a division condition; all the combat platforms are subjected to dimension reduction clustering in sequence. According to the method, the high-dimensional complex calculation degree generated in the killer chain reconstruction process is subjected to dimension reduction processing, the calculation amount is remarkably reduced, and the reconstruction time is shortened.
Owner:NORTHWESTERN POLYTECHNICAL UNIV +1

Anti-killer chain construction method based on service-oriented killer chain

The invention relates to the technical field of killer chain construction, in particular to an anti-killer chain construction method based on a service-oriented killer chain, and provides the following scheme: target motion prediction is performed based on real-time state information of a to-be-hit target to obtain a predicted path of the target in a preset time, and a probability cloud model is constructed in a three-dimensional tactical space to obtain a predicted path of the target; and a target influence area is determined after tactical environment constraint correction. And screening candidate service objects from the service resource library according to space, time and capability constraints, and mapping the candidate service objects to each killing chain link in combination with the service type killing chain template corresponding to the target. According to the method, rapid reconstruction of the killing chain can be realized under the conditions of target maneuvering, equipment damage or resource replacement, and the flexibility and continuous strike capability of a combat system are improved.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

CPS attack path reconstruction method and system based on killer chain model clustering

The invention belongs to the technical field of network security, and particularly relates to a CPS attack path reconstruction method and system based on killer chain model clustering. The method comprises the steps of collecting operation data of a CPS information layer and a physical layer, generating feature vectors through time window fusion, dividing feature subspaces based on four stages of a killing chain, clustering data of each stage to obtain candidate clusters, screening high-credibility clusters in combination with time concentration and behavior intensity, and constructing a causal graph according to time proximity and cross-layer correlation. Complete reconstruction of an attack path is realized; the method adapts to CPS cross-layer coupling characteristics, improves the accuracy of attack stage division and path reconstruction, and can provide reliable support for attack traceability and defense strategy formulation.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Urban unmanned aerial vehicle defense-oriented disposal strategy automatic generation system

The invention discloses an urban unmanned aerial vehicle defense-oriented disposal strategy automatic generation system, and the system comprises an initialization module which is used for carrying out initialization; the situation information updating module is used for continuously receiving the situation information and instantiating the incoming target; the killing network construction module is used for sequentially calculating a connection relationship among a target node, an interception equipment node and a detection equipment node in the killing network to form the killing network; the killing chain optimization module is used for monitoring the integrity of the killing chain where each target is located and maintaining the original killing chain or regenerating the killing chain according to the monitoring result; and the self-evolution module is used for realizing iterative optimization updating of artificial neural network parameters in the killing chain optimization module by accumulating actual combat data and a reinforcement learning method, so that the model generates a better unmanned aerial vehicle disposal strategy. According to the technical scheme, the problem that the killing chain is interrupted due to factors such as building shielding in the urban environment can be solved, and rapid and effective maintenance of the killing network based on the real-time situation is ensured.
Owner:JIANGNAN ELECTROMECHANICAL DESIGN INST +1

A method for generating kill chains and recommending remediation action

A method includes, for each vulnerability in a set of vulnerabilities: deriving a correlation between the vulnerability and an attack technique based on language signals detected in descriptions of the vulnerability; constructing a vulnerability module defining the attack technique and representing the vulnerability; detecting a second vulnerability preceding exploitation of the vulnerability in the corpus of threat intelligence; defining the second vulnerability as an input vulnerability in the vulnerability module; detecting a third vulnerability succeeding exploitation of the vulnerability in the corpus of threat intelligence; defining the third vulnerability as an output vulnerability in the vulnerability module; interpreting an access tier of the vulnerability based on characteristics of the attack technique; accessing a vulnerability risk score for the vulnerability; interpreting a mitigation technique for the attack technique; and annotating the vulnerability module with the access tier, the vulnerability risk score, and the mitigation technique.
Owner:TEGULA LLC

Systems and methods for countering persistent malware

Some embodiments construct an entity map describing a group of inter-related entities and determine whether a computing device comprises malware according to the respective entity map. The entity map includes worker entities (e.g., processes) and resource entities (e.g., files) accessed by the respective worker entities. Some entity maps are persistently stored and recovered in response to a reboot, enabling a complete reconstruction of a kill chain even when malicious activities are distributed among multiple entities and multiple computing sessions. Some embodiments detect infection by comparing a current entity map with a signature map describing at least a fragment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

A causal reasoning-based APT kill chain reconstruction and prediction method and system

The present invention relates to the technical field of APT kill chain reconstruction and prediction methods, and provides an APT kill chain reconstruction and prediction method and system based on causal reasoning. The method aims to address the problems existing in existing APT detection and defense technologies, such as difficulty integrating multi-source heterogeneous data, insufficient spatiotemporal dynamic feature modeling, inaccurate kill chain reconstruction, limited predictive capabilities, poor interpretability, and difficulty balancing real-time and accuracy. The method comprises acquiring multi-source heterogeneous data, constructing a causal graph, performing multimodal feature extraction based on the causal graph to obtain initial node feature representations; inputting the initial node feature representations into a temporal causal graph convolutional learning algorithm to obtain optimized node representations; performing kill chain reconstruction based on the optimized node representations to obtain possible kill chain sequences; predicting future attack paths based on the possible kill chain sequences to obtain potential attack paths; and generating an interpretable analysis report based on the potential attack paths.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Kill chain identifications

An example storage medium stores instructions that, when executed, cause a processor of a computing device to receive an indication associated with a first virtual machine, the first virtual machine containing a first application, the indication indicating that a first operation in the first virtual machine is to use a second application; receive information associated with a second virtual machine, the second virtual machine created in response to the first operation and containing the second application; store information describing a chain of virtual machines, the chain of virtual machines including the first and second virtual machines, the stored information including a relationship between the first virtual machine and the second virtual machine, based on the received indication and the received information; and in response to an identification of malware in the chain of virtual machines, identify a particular virtual machine in the chain of virtual machines that is in a kill chain of the malware based on the stored information.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Systems and methods for countering persistent malware

Some embodiments construct an entity map describing a group of inter-related entities and determine whether a computing device comprises malware according to the respective entity map. The entity map includes worker entities (e.g., processes) and resource entities (e.g., files) accessed by the respective worker entities. Some entity maps are persistently stored and recovered in response to a reboot, enabling a complete reconstruction of a kill chain even when malicious activities are distributed among multiple entities and multiple computing sessions. Some embodiments detect infection by comparing a current entity map with a signature map describing at least a fragment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

A dynamic kill chain construction and reconfiguration method and apparatus

The application discloses a dynamic killing chain construction and reconstruction method and device, which acquires real-time situation data and constructs a time-varying heterogeneous graph for representing a connection relationship of heterogeneous nodes and multi-dimensional constraints, performs phased searching in the time-varying heterogeneous graph based on a task demand, generates a candidate killing chain set containing a main chain and a backup chain, executes feasibility screening on the candidate killing chain set to eliminate chains that do not satisfy hard constraints and obtains a feasible chain set, then performs multi-objective collaborative optimization selection on the feasible chain set, outputs a backup chain set and a target main chain, and finally, when a node state change triggering a reconstruction condition is monitored, performs a hierarchical reconstruction operation based on the target main chain, the backup chain set and a time-varying heterogeneous graph updated in real time to generate an updated killing chain execution scheme.
Owner:BAIYANG TIMES (BEIJING) TECH CO LTD

A dynamic kill chain construction and reconfiguration method and apparatus

The application discloses a dynamic killing chain construction and reconstruction method and device, which acquires real-time situation data and constructs a time-varying heterogeneous graph for representing a connection relationship of heterogeneous nodes and multi-dimensional constraints, performs phased searching in the time-varying heterogeneous graph based on a task demand, generates a candidate killing chain set containing a main chain and a backup chain, executes feasibility screening on the candidate killing chain set to eliminate chains that do not satisfy hard constraints and obtains a feasible chain set, then performs multi-objective collaborative optimization selection on the feasible chain set, outputs a backup chain set and a target main chain, and finally, when a node state change triggering a reconstruction condition is monitored, performs a hierarchical reconstruction operation based on the target main chain, the backup chain set and a time-varying heterogeneous graph updated in real time, and generates an updated killing chain execution scheme.
Owner:BAIYANG TIMES (BEIJING) TECH CO LTD

Test method, device, storage medium and electronic equipment for satellite system security

Embodiments of the present disclosure provide a test method and device for satellite system security, a storage medium and an electronic device. The test method comprises: performing directional threat assessment on a composite kill chain of the satellite system to obtain a threat assessment result; performing threat deduction on a network space model of the satellite system to obtain a threat deduction result; and determining a defense action matrix based on the threat assessment result and the threat deduction result. Embodiments of the present disclosure construct a composite kill chain based on real-world real scenarios, effectively improve the defense coverage of the satellite system, enhance the security protection of the satellite system by determining potential threats that may exist in the satellite system, promote the improvement of the security countermeasure capability of the satellite system, form a benign mechanism and mature means that can be universally applied to the security protection deduction test of the satellite system of the army, and thus ensure the security of the satellite system under modern and future war conditions.
Owner:HARBIN ANTIY TECH

A Dynamic Defense Method and System for APT Network Kill Chain Based on Dual Deep Reinforcement Learning

A dynamic defense method and system for APT network kill chains based on dual deep reinforcement learning is proposed. The system pre-configures a network system including host nodes, security defenders, malicious attackers, and security defense devices. Malicious attackers execute attacks on host nodes according to the network kill chain. Security defenders monitor these attacks and acquire network status. Security defense devices, based on dual deep reinforcement learning algorithms and combined with the network status, dynamically generate optimal defense strategies and feed them back to the security defenders. The security defenders then dynamically respond to the attacks using these optimal strategies to protect against the network kill chain. This approach achieves efficient identification and accurate response to APT attacks, effectively improving system security and resource utilization efficiency. It provides an innovative solution for dynamic defense in complex network environments and significantly enhances the resistance to APT attacks.
Owner:XIAMEN UNIV

Killer chain construction method based on particle swarm optimization

The invention discloses a killing chain construction method based on a particle swarm algorithm, and belongs to the technical field of cooperative combat systems. The method comprises the following steps: dividing a killing chain construction problem into four links of detection, positioning, interference and strike which are executed in sequence, respectively establishing corresponding task allocation models, and taking maximization of efficiency of each link as a target function; and solving each link model by adopting an improved decimal discrete particle swarm algorithm to obtain an optimal task allocation scheme, and sequentially combining all link schemes to complete the construction of the killing chain. According to the method, the modeling process is simplified, the calculation efficiency is improved, the method is suitable for a large-scale combat scene, an optimization scheme can be quickly generated, and the requirements of actual combat for real-time performance and accuracy are effectively met.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Collaborative strategy-based killer chain construction method, apparatus and device, and medium

The invention provides a killing chain construction method and device based on a collaborative strategy, equipment and a medium. The killing chain construction method based on the collaborative strategy comprises the steps that target information of an attacking target is acquired through a UCN network; according to the network topology of the UCN network, the target information and a first constraint condition, determining a killing chain of the target to be attacked through a link selector by adopting a shortest path algorithm; according to the killing chain and a second constraint condition, carrying out resource processing on the platform of the UCN network by adopting a resource allocator to obtain a resource allocation result; and according to the killing chain and the resource allocation result, executing attack processing of the attack target through the UCN network. The device has the beneficial effects that the striking efficiency is improved, and the striking consumption is reduced.
Owner:NAT UNIV OF DEFENSE TECH

An effectiveness evaluation method based on modeling of an anti-system-of-systems kill chain

This invention discloses an effectiveness evaluation method based on kill chain modeling of an adversarial system, belonging to the field of system evaluation technology. The method includes the following steps: based on the starting and ending conditions of a given task, analysis is performed in three different dimensions: time, information, and precision. An adversarial interaction network is constructed, and the adversarial effectiveness is analyzed in different dimensions using the analytic hierarchy process (AHP), with scores assigned to the evaluation results in each dimension. The scores of the evaluation results in different dimensions are then weighted and integrated to obtain a comprehensive evaluation result of the adversarial effectiveness. This invention fully considers the influence of each node in the adversarial system on the system's adversarial effectiveness, highlighting the significant impact of the kill chain in the time, information, and precision dimensions on effectiveness. It solves the problem of evaluating the strike effectiveness of kill chains formed by different adversarial methods in complex systems.
Owner:HARBIN ENG UNIV

Method and apparatus for generating kill chain stage, electronic device and storage medium

Embodiments of the present application provide a method and device for generating a kill chain phase, electronic equipment and a storage medium, belonging to the technical field of network security. First association information about the kill chain phase is obtained from detection data of attack behavior, and second association information is obtained by expanding the first association information according to the attack behavior, so as to expand the kill chain related information of the attack behavior. Then, multiple kill chain phases of the attack behavior and feature information of the kill chain phases are generated according to the expanded second association information. Furthermore, the kill chain phases are modified and stored according to the editing information obtained after detecting each kill chain phase. As a result, multiple kill chain phases are expanded based on the second association information obtained after information expansion, which greatly improves the richness of the kill chain phase information.
Owner:BEIJING KNOWNSEC INFORMATION TECHNOLOGY CO LTD

A method for constructing an anti-kill chain based on a service-type kill chain

The application relates to the technical field of killing chain construction, in particular to a counter-killing chain construction method based on a service type killing chain. The application proposes the following scheme: target motion prediction is carried out based on real-time state information of a to-be-struck target, a predicted path of the target within a preset time is obtained, a probability cloud model is constructed in a three-dimensional tactical space, and a target influence area is determined after being corrected by a tactical environment constraint. Candidate service objects are screened from a service resource library according to space, time and capacity constraints, and the candidate service objects are mapped to each killing chain link in combination with a service type killing chain template corresponding to the target. The application can realize rapid reconstruction of the killing chain under the conditions of target maneuvering, equipment damage or resource replacement, and improve the flexibility and sustained striking capacity of a combat system.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Multi-dimensional equipment system contribution rate evaluation method

The invention discloses a multi-dimensional equipment system contribution rate evaluation method, which comprises the following steps of: 1, acquiring network topology structure information of an equipment system, and collecting the total number of combat resources and detection information of a sensor on an incoming target; step 2, establishing a calculation model of the total number of killing chains of the equipment system based on a system network topology structure; 3, establishing an incoming attack target value evaluation index system, and evaluating the strategic / tactical value of the incoming attack target; step 4, simulating a combat scene, and obtaining the number of resources consumed by each device and hit / damage of an incoming attack target; 5, evaluating a contribution rate evaluation index of the equipment in a system combat effectiveness dimension, and evaluating a relative contribution rate of the equipment in a resource consumption and target value hitting dimension based on a relative increment model; step 6, establishing an equipment comprehensive contribution rate calculation model, and evaluating the comprehensive contribution rate of each piece of equipment; and step 7, outputting a comprehensive contribution rate evaluation result of each equipment system. Influences of indexes such as combat effectiveness, combat consumption and combat income can be considered, and managers are helped to comprehensively evaluate the contribution rate of the equipment system.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA