网络与信息安全学报 ›› 2022, Vol. 8 ›› Issue (1): 1-14.doi: 10.11959/j.issn.2096-109x.2021089

• 综述 •    下一篇

基于攻防博弈的网络防御决策方法研究综述

刘小虎, 张恒巍, 马军强, 张玉臣, 谭晶磊   

  1. 信息工程大学,河南 郑州 450001
  • 修回日期:2021-03-15 出版日期:2022-02-15 发布日期:2022-02-01
  • 作者简介:刘小虎(1989− ),男,河南太康人,博士,信息工程大学副教授,主要研究方向为网络攻防博弈
    张恒巍(1977− ),男,河南洛阳人,信息工程大学副教授,主要研究方向为网络安全风险评估、网络攻防博弈
    马军强(1975− ),男,陕西大荔人,信息工程大学副教授,主要研究方向为指挥与管理
    张玉臣(1977− ),男,河南新郑人,信息工程大学教授、博士生导师,主要研究方向为保密管理
    谭晶磊(1994− ),男,山东章丘人,信息工程大学博士生,主要研究方向为移动目标防御
  • 基金资助:
    国家重点研发计划(2017YFB0801900);河南省科技攻关(222102210017)

Research review of network defense decision-making methods based on attack and defense game

Xiaohu LIU, Hengwei ZHANG, Junqiang MA, Yuchen ZHANG, Jinglei TAN   

  1. Information Engineering University, Zhengzhou 450001, China
  • Revised:2021-03-15 Online:2022-02-15 Published:2022-02-01
  • Supported by:
    The National Key R&D Program of China(2017YFB0801900);Henan Science and Technology(222102210017)

摘要:

博弈论研究冲突对抗条件下最优决策问题,是网络空间安全的基础理论之一,能够为解决网络防御决策问题提供理论依据。提炼网络攻防所具备的目标对立、策略依存、关系非合作、信息不完备、动态演化和利益驱动 6 个方面博弈特征。在理性局中人假设和资源有限性假设的基础上,采用攻防局中人、攻防策略集、攻防动作集、攻防信息集和攻防收益形式化定义了五元组网络攻防博弈模型,分析了博弈均衡的存在条件,总结出基于攻防博弈模型的网络防御决策过程。梳理分析了基于完全信息静态博弈、完全信息动态博弈、不完全信息静态博弈、不完全信息动态博弈、演化博弈、微分博弈、时间博弈和随机博弈共8种不同类型博弈模型的网络防御决策方法的适用场景,综述其研究思路,给出基于不同类型博弈模型的网络防御决策方法的优缺点。总结基于攻防博弈的网络防御决策方法的发展过程,说明防御决策方法具备的优势特点;指出研究过程中面临着博弈建模考虑因素与模型复杂度的关系,博弈推理对信息和数据的依赖性,博弈模型的泛化性和迁移性3个问题;并从规范策略的描述机制、优化收益的计算方法以及与其他网络安全技术相互融合3个方面展望了下一步研究方向,说明需要重点解决的问题。

关键词: 网络防御, 决策方法, 攻防博弈, 博弈特征

Abstract:

Game theory studies the optimal decision-making problem under the condition of conflict confrontation.It is one of the basic theories of cyberspace security, and can provide a theoretical basis for solving the problem of network defense decision-making.The six game characteristics of network attack and defense were defined, such as goal opposition, strategy dependence, non-cooperative relationship, incomplete information, dynamic evolution and interest drive.Based on the hypothesis of rational player and limited resources, a 5-tuple network attack and defense game model was formally defined by using player, attack and defense strategy set, attack and defense action set, attack and defense information set and attack and defense income.The existing conditions of game equilibrium were analyzed, and the general process of network defense decision-making based on attack and defense game model was summarized.The applicable scenarios of network defense decision-making methods based on eight different types of game models were analyzed, such as complete information static game, complete information dynamic game, incomplete information static game, incomplete information dynamic game, evolutionary game, differential game, time game and random game, and summarizes their research ideas.The advantages and disadvantages of network defense decision-making methods based on different types of game models were given.The development process of network defense decision-making method based on attack defense game was summarized, and the advantages and characteristics of defense decision-making method was explained.It were pointed out that there were three problems in the research process, such as the relationship between the number of factors considered in game modeling and the complexity of the model, the dependence of game reasoning on information and data, and the generalization and migration of game model.It also looked forward to the next research direction from the description mechanism of normative strategy, the calculation method of optimizing revenue and the integration with other network security technologies.And the problems that should be solved were explained.

Key words: network defense, decision-making methods, attack and defense game, game characteristic

中图分类号: 

No Suggested Reading articles found!