电信科学 ›› 2024, Vol. 40 ›› Issue (2): 47-55.doi: 10.11959/j.issn.1000-0801.2024020

• 研究与开发 • 上一篇    

APT攻击下的无线通信网络最优主动防御决策模型

孟勐, 王丹妮, 吕军, 张福良   

  1. 国网辽宁省电力有限公司信息通信分公司,辽宁 沈阳 110006
  • 修回日期:2023-12-13 出版日期:2024-02-01 发布日期:2024-02-01
  • 作者简介:孟勐(1991- ),男,国网辽宁省电力有限公司信息通信分公司工程师,主要研究方向为网络安全防御决策、漏洞挖掘等
    王丹妮(1986- ),女,国网辽宁省电力有限公司信息通信分公司高级工程师,主要研究方向为网络安全前沿技术、技防体系建设等
    吕军(1987- ),男,国网辽宁省电力有限公司信息通信分公司高级工程师,主要研究方向为网络与信息安全
    张福良(1989- ),男,国网辽宁省电力有限公司信息通信分公司高级工程师,主要研究方向为数据挖掘与分析
  • 基金资助:
    国网辽宁省电力有限公司科技项目(2022YF-101)

Optimal active defense decision model of wireless communication network under APT attack

Meng MENG, Danni WANG, Jun LYU, Fuliang ZHANG   

  1. State Grid Liaoning Electric Power Supply Co., Ltd., Information &Telecommunication Branch, Shenyang 110006, China
  • Revised:2023-12-13 Online:2024-02-01 Published:2024-02-01
  • Supported by:
    Science and Technology Project of State Grid Liaoning Electric Power Co., Ltd.(2022YF-101)

摘要:

最优主动防御决策可以保障无线通信网络的安全稳定性,为了提高无线通信网络的防御效果,提出了APT攻击下的无线通信网络最优主动防御决策模型。关联无线通信网络日志,构建APT攻击对象集合,通过反馈相容系数计算APT攻击事件的绝对相容度,并预测APT攻击行为。基于APT攻击源对无线通信网络攻击的信道带宽,获取无线通信网络受到APT攻击的位置,利用无线通信网络节点的权值系数,提取无线通信网络的APT攻击特征。利用攻防图,计算得到APT攻击对无线通信网络的损害程度,通过定义无线通信网络的安全状态,构建了无线通信网络最优主动防御决策模型。实验结果表明,所提模型在防御无线通信网络的APT攻击时,可以将攻击数据包拒包率和吞吐量分别提高到90%以上和16 000 bit/s以上,并且时延较低,具有更好的防御效果。

关键词: APT攻击, 主动防御, 特征提取, 攻击趋势, 无线通信网络, 决策模型

Abstract:

The optimal active defense decision can ensure the security and stability of wireless communication networks.In order to improve the defense effectiveness of wireless communication networks, an optimal active defense decision model for wireless communication networks under APT attacks was proposed.Wireless communication network logs were associated, a set of APT attack objects were constructed, the absolute compatibility of APT attack events was calculated through feedback compatibility coefficients, and APT attack behaviors were predicted.Based on the channel bandwidth of APT attack sources on wireless communication networks, the location of the wireless communication network being attacked by APT was obtained, and the weight coefficients of wireless communication network nodes were used to extract the APT attack characteristics of the wireless communication network.Using the attack and defense diagram, the degree of damage caused by APT attacks to wireless communication networks was calculated.By defining the security status of wireless communication networks, an optimal active defense decision model for wireless communication networks was constructed.The experimental results show that the proposed model can increase the packet rejection rate and throughput of attack packets to over 90% and 16 000 bit/s respectively when defending against APT attacks in wireless communication networks, with lower time delay and better defense effectiveness.

Key words: APT attack, active defense, feature extraction, attack trend, wireless communication network, decision model

中图分类号: 

No Suggested Reading articles found!