The content of the invention
The technical problem to be solved in the present invention is that game quantized data how is provided during network attack.
Therefore, according in a first aspect, the embodiment of the invention discloses a kind of betting data analysis method, including:
Obtain the game avail data of a upper node;Obtain the action and identity of the game participant of present node;
The action and identity of the game participant according to present node determine the current action income of present node game participant;
Game avail data and current action income according to a upper node obtain the game avail data of present node.
Alternatively, the game avail data and current action income according to a upper node obtain the game income of present node
Data include:Game avail data and current action income summation to a upper node obtains the game income number of present node
According to.
Alternatively, the action and identity of the game participant according to present node determines present node game participant
Current action income include:The action and identity of the game participant according to present node obtain the influence of present node
The factor, factor of influence is the parameter obtained according to sample data study;Factor of influence according to present node determines present node
The current action income of game participant.
Alternatively, the factor of influence of present node is obtained using equation below:Impact (a)=wCC(a)+wIC(a)+wAC
(a), wherein, a is the action of present node game participant, and Impact (a) is the factor of influence of present node, wC、wIAnd wAPoint
It is not the weight coefficient of the confidentiality relevant with current action, integrality and availability, C (a) is the default of present node action
Value.
Alternatively, the factor of influence according to present node determines the current action income bag of present node game participant
Include:When the action of present node game participant is to attack:If the identity of present node game participant is attack
Person, then income of the attacker under current action is d × Impact (a), wherein, d is constant coefficient, and Impact (a) is to work as prosthomere
The factor of influence of point;If the identity of present node game participant is defender, defender is under current action
Income is-Impact (a)d;When the action of present node game participant is for defence:If present node game participant's
Identity is attacker, then income of the attacker under current action is 0;If the identity mark of present node game participant
It is defender to know, then income of the defender under current action is Impact (a).
According to second aspect, the embodiment of the invention discloses a kind of betting data analytical equipment, including:
First acquisition module, the game avail data for obtaining a upper node;Second acquisition module, it is current for obtaining
The action and identity of the game participant of node;Action income module, for the game participant's according to present node
Action and identity determine the current action income of present node game participant;Current income module, for according to upper one
The game avail data and current action income of node obtain the game avail data of present node.
Alternatively, current income module is used to obtain game avail data and current action the income summation of a upper node
The game avail data of present node.
Alternatively, action income module includes:The factor obtains unit, for the dynamic of the game participant according to present node
Work and identity obtain the factor of influence of present node, and factor of influence is the parameter obtained according to sample data study;Income
Determining unit, the current action income for determining present node game participant according to the factor of influence of present node.
Alternatively, the factor obtains the factor of influence that unit obtains present node using equation below:Impact (a)=wCC
(a)+wIC(a)+wAC (a), wherein, a for present node game participant action, Impact (a) for present node influence because
Son, wC、wIAnd wAThe weight coefficient of confidentiality, integrality and availability respectively relevant with current action, C (a) is to work as prosthomere
The default value of point action.
Alternatively, income determining unit includes:First subelement, for being to attack when the action of present node game participant
When hitting:If the identity of present node game participant be attacker, income of the attacker under current action be d ×
Impact (a), wherein, d is constant coefficient, and Impact (a) is the factor of influence of present node;If present node game participant
Identity be defender, then income of the defender under current action be-Impact (a)d;Second subelement, for working as
When the action of present node game participant is for defence:If the identity of present node game participant is attacker,
Income of the attacker under current action is 0;If the identity of present node game participant is defender, defender
Income under current action is Impact (a).
Technical solution of the present invention, has the following advantages that:
Betting data analysis method provided in an embodiment of the present invention and device, due to the game participant according to present node
Action and identity determine the current action income of present node game participant, then, according to the game of a upper node
Avail data and current action income obtain the game avail data of present node such that it is able to for present node game provides rich
Quantized data is played chess, provides objective data foundation can then to the Analysis of Policy Making of safety management.Additionally, according to a upper node
Game avail data obtains the game avail data of present node such that it is able to reduce the amount of analysis of present node income determination,
Improve analysis efficiency.
Specific embodiment
Technical scheme is clearly and completely described below in conjunction with accompanying drawing, it is clear that described implementation
Example is a part of embodiment of the invention, rather than whole embodiments.Based on the embodiment in the present invention, ordinary skill
The every other embodiment that personnel are obtained under the premise of creative work is not made, belongs to the scope of protection of the invention.
In the description of the invention, it is necessary to explanation, term " " center ", " on ", D score, "left", "right", " vertical ",
The orientation or position relationship of the instruction such as " level ", " interior ", " outward " be based on orientation shown in the drawings or position relationship, merely to
Be easy to the description present invention and simplify describe, rather than indicate imply signified device or element must have specific orientation,
With specific azimuth configuration and operation, therefore it is not considered as limiting the invention.Additionally, term " first ", " second ",
" the 3rd " is only used for describing purpose, and it is not intended that indicating or implying relative importance.
In the description of the invention, it is necessary to illustrate, unless otherwise clearly defined and limited, term " installation ", " phase
Company ", " connection " should be interpreted broadly, for example, it may be being fixedly connected, or being detachably connected, or be integrally connected;Can
Being to mechanically connect, or electrically connect;Can be joined directly together, it is also possible to be indirectly connected to by intermediary, can be with
It is two connections of element internal, can is wireless connection, or wired connection.For one of ordinary skill in the art
For, above-mentioned term concrete meaning in the present invention can be understood with concrete condition.
As long as additionally, technical characteristic involved in invention described below different embodiments non-structure each other
Can just be combined with each other into conflict.
In order to provide game quantized data during network attack, present embodiment discloses a kind of betting data analysis side
Method, refer to Fig. 1, be the betting data analysis method flow chart, and the method comprises the following steps:
Step S100, obtains the game avail data U of a upper noded-1, wherein, d is the integer more than or equal to 1.In tool
In body embodiment, according to actual needs, game of the game both sides (attacker and defender) in a upper node can be respectively obtained
Avail data Ud-1To analyze the game income of current game both sides respectively;The game income of a node in an acquisition can also be selected
Data Ud-1To analyze the game income of current a certain participant.It should be noted that in a particular embodiment, as d=1, on
One node be root node, generally at root node (d-1=0), game both sides do not act, can the income zero setting of two participants,
Game avail data i.e. in root node both sides is 0.
Step S200, obtains the action and identity of the game participant of present node.In a particular embodiment, due to
In action, the income of the applying side of game action can increase any one party of game both sides, the receipts of the contra of game action
Benefit can be reduced.Therefore, in order to realize the income of present node game both sides, it is necessary to obtain work and the identity mark of game participant
Know, in the present embodiment, alleged identity is used to distinguish the attacker and defender of game both sides.
Step S300, the action and identity of the game participant according to present node determine that present node game is participated in
The current action income B of person.In a particular embodiment, the identity of current game participant, and the participant are being obtained
After performed action, can determine that current action gives game both sides institute band according to the identity of participant and the attribute of action
The action income B for coming.Specifically, can rule of thumb determine the brought action income B of each action, obtain participant's
After action and identity, corresponding action income B can be directly extracted.
Step S400, the game avail data U according to a upper noded-1The rich of present node is obtained with current action income B
Play chess avail data Ud.In a particular embodiment, can be to the game avail data U of a upper noded-1Asked with current action income B
With the game avail data U for obtaining present noded.Specifically, the rich of present node can be calculated using equation below
Play chess avail data Ud:
Ud(p, a)=Ud-1(p,a')+B(p,a,d) (1)
Wherein, Ud(p, a) is the income of present node, and d is the node depth of present node, and p is identified for participant, and a is
The action of participant, B (p, a, d) is the current action income produced by participant p present node depth d implementations action a.According to
Knowable to formula (1), a node game avail data U in acquisitiond-1Afterwards, it may not be necessary to know that upper node participant carries out dynamic
Make the action income of a ', i.e.,:The game avail data U of present noded(p, a) with the game avail data U of a upper noded-1(p,
A') and present node current action income B (p, a, d) it is relevant.For root node, due to game, both sides do not act, can
With by the game avail data zero setting of game both sides, i.e. U0=0.
In an alternate embodiment of the invention, when step S300 is performed, the action of the game participant according to present node and body
Part mark determines that the current action income B of present node game participant can include:Game participant according to present node
Action and identity obtain the factor of influence of present node, factor of influence is the parameter obtained according to sample data study;
Factor of influence according to present node determines the current action income B of present node game participant.
In a particular embodiment, produced shadow when can be calculated present node execution action a using equation below
Ring factor Impact (a):
Impact (a)=wCC(a)+wIC(a)+wAC(a) (2)
Wherein, a is the action of present node game participant, and Impact (a) is the factor of influence of present node, generally may be used
Beforehand through the data produced by each action to each participant to carry out offline or on-line study, to obtain different action institutes right
The factor of influence size answered, wC、wIAnd wAThe weighting system of confidentiality, integrality and availability respectively relevant with current action
Number, C (a) is the default value of present node action.In a particular embodiment, preset value C (a) can with empirically determined,
Specifically, history samples data can be analyzed and is obtained, it can be [0,10] for example to preset value C (a) span.Make
It is example, it is assumed that intelligent grid SCADA sensor networks are a given shielded assets, intelligent grid SCADA system
Used as sensor network, its main function is to send and receive data in sensor communication, therefore, in three secure contexts
Data integrity is mostly important, next to that availability, is again confidentiality, because data are ravesdropping does not necessarily represent number
According to loss.Here, we can be according to three importance of aspect come to the grade and correspondingly quantization parameter for dividing weight, i.e.,
wI> wA> wC, for example, can make wI=0.6, wA=0.3, wC=0.1.
In a particular embodiment, the factor of influence according to present node determines the current action of present node game participant
Income B can include:
When the action of present node game participant is to attack A (a is the action of A):
If the identity of present node game participant is attacker, income B of the attacker under current action
It is d × Impact (a), wherein, d is constant coefficient, and Impact (a) is the factor of influence of present node;If present node game
The identity of participant is defender, then income B of the defender under current action is-Impact (a)d;
When the action of present node game participant is for defence D (a is the action of D):
If the identity of present node game participant is attacker, income B of the attacker under current action
It is 0;If the identity of present node game participant is defender, income B of the defender under current action is
Impact(a)。
Specifically, refer to following table:
Table 1
B(p,a,d) |
A is the action of A |
A is the action of D |
Attacker |
d×Impact(a) |
0 |
Defender |
-Impact(a)d |
Impact(a) |
In sum, game both sides participant p (attacker and defender) present node depth can be respectively obtained by table 1
Current action income B (p, a, d) produced by degree d implementation actions a.
For ease of it will be appreciated by those skilled in the art that being illustrated with specific example below:
The sensor network of SCADA system is supplied comprising perception with the sensor of gathered data and for data processing, electric power
Should be with the modules of communication.All RTUs (Remote Terminal Unit, RTU) by SCADA system
The data that module is detected all can be by convergence in real time.The most common threat of intelligent grid SCADA sensor networks mainly has
Four types (attack A):Sybil is attacked, node is compromised, eavesdrop, data are injected, and might as well set these attacks A difference
It is aS、aNC、aeAnd aDI。
For these attacks, betting model is built, define the action of attacker A and defender D:
Sybil is attacked and node is compromised enters sensor network by destroying sensor node, and eavesdrops and data
Injection is only the final purpose of attacker, i.e. the action of A includes that mentioned immediately above four kinds are attacked (if do not produce action to be acting
anil)。
And the defence on the practical significance of SCADA sensor networks is the detection and control of RTU.RTU is not only managed and passed
The energy and broadcast control information of sensor node but also the sensor of abnormal behaviour can be removed, safeguard global routing table,
Submit detection data to and send an alert to MTU (Maximum Transmission Unit, MTU) in case SCADA
Broken down between sensor network and RTU networks, sensor network agency mainly takes following three points to act (defence to attacking
Action D):(1)reCompletely cut off the energy of sensor;(2)raIt is to send alarm to MTU;(3)rmMajor corrections data and effective node.
Because using arriving all in each step, individually how influence attacker does not take his attack next time to move for these actions
Make, we can be considered as these actions one defense reaction motor unit of game<re, ra, rm>, defender D do not produce
R is used during actionnilRepresent.
Next, the shadow that the information assets based on it to three secure contexts (integrality, availability and confidentiality) is produced
Ring to quantify the influence of each action.With reference to the weight that formula (2) is mentioned, the influence of each action can be drawn, obtain working as prosthomere
Factor of influence Impact (a) of the action of point, as shown in table 2:
Table 2
Action a |
Description |
wCC(a) |
wIC(a) |
wAC(a) |
Impact(a) |
<re, ra, rm> |
Defence |
6 |
6 |
1 |
4.5 |
aS |
Sybil is attacked |
6 |
1 |
1 |
1.5 |
aNC |
Node is compromised |
6 |
1 |
1 |
1.5 |
ae |
Eavesdropping |
8 |
1 |
1 |
1.7 |
aDI |
Data are injected |
1 |
8 |
6 |
6.7 |
Data display shows in table 2, and for attacker, completeness and availability make data inject with highest shadow
Value is rung, is 6.7.
Next the analysis to game theory:
Fig. 2 is refer to, is this example betting model tree, each node of game theory has the corresponding income form of expression
(A ' s payoff, D ' s payoff), wherein, A ' s payoff represent the income of present node attacker A, D ' s payoff tables
Show the income of present node defender D.Income can be by formula (1) and formula (2) and the behavioral implications shown in Tables 1 and 2
To calculate.It should be noted that the numerical value of " () " is the income example of present node game both sides in accompanying drawing 2.
From root node pay for (0,0) as attacker A decision node, and attacker A can only carry out node compromise or
Sybil is attacked and is gone to destroy SCADA sensor networks, and the second layer is then the reaction of defender D, but it can not be by action<re, ra,
rm>Or other any modes are defendd.No matter A root node select be what act, if defender D is not defendd, attack
The person of hitting A just can continue to be eavesdropped or data injection.
Assuming that in root node, after defender D has made the alarm that defence sends malicious node to RMU, attacker A hairs
Go out Sybil attacks, even if Sybil nodes attempt injecting data, but the controller of RTU can abandon abnormal data, note data
It is invalid to enter.Sybil nodes can make it possible eavesdropping as tie point.If additionally, attacker A carries out node in root node
Compromise and attack, defender D is defendd by eliminating compromise node, then A will be unable to further be attacked.
The present embodiment also discloses a kind of betting data analytical equipment, refer to Fig. 3, is the betting data analytical equipment knot
Structure schematic diagram, the betting data analytical equipment includes:First acquisition module 100, the second acquisition module 200, action income module
300 and current income module 400, wherein:
First acquisition module 100 is used to obtain the game avail data U of a noded-1, wherein, d is more than or equal to 1
Integer;Second acquisition module 200 is used for the action and identity of the game participant for obtaining present node;Action income mould
The action and identity that block 300 is used for the game participant according to present node determine that present node game participant's is current
Action income B;Current income module 400 is used for the game avail data U according to a upper noded-1Obtained with current action income B
The game avail data U of present noded。
In an alternate embodiment of the invention, current income module is used for the game avail data U to a upper noded-1It is dynamic with current
Make the game avail data U that income B summations obtain present noded。
In an alternate embodiment of the invention, action income module includes:The factor obtains unit, for the game according to present node
The action and identity of participant obtain the factor of influence of present node;Income determining unit, for according to present node
Factor of influence determines the current action income B of present node game participant.
In an alternate embodiment of the invention, the factor obtains the factor of influence that unit obtains present node using equation below:
Impact (a)=wCC(a)+wIC(a)+wAC (a), wherein, a is the action of present node game participant, and Impact (a) is to work as
The factor of influence of front nodal point, wC、wIAnd wAThe weighting system of confidentiality, integrality and availability respectively relevant with current action
Number, C (a) is the default value of present node action.
In an alternate embodiment of the invention, income determining unit includes:First subelement, for as present node game participant
Action for attack when:If the identity of present node game participant is attacker, attacker is under current action
Income B be d × Impact (a), wherein, d is constant coefficient, and Impact (a) is the factor of influence of present node;If working as prosthomere
The identity of point game participant is defender, then income B of the defender under current action is-Impact (a)d;Second
Subelement, for when the action of present node game participant is for defence:If the identity mark of present node game participant
It is attacker to know, then income B of the attacker under current action is 0;If the identity of present node game participant is
Defender, then income B of the defender under current action is Impact (a).
Betting data analysis method provided in an embodiment of the present invention and device, due to the game participant according to present node
Action and identity determine the current action income of present node game participant, then, according to the game of a upper node
Avail data and current action income obtain the game avail data of present node such that it is able to for present node game provides rich
Quantized data is played chess, provides objective data foundation can then to the Analysis of Policy Making of safety management.Additionally, according to a upper node
Game avail data obtains the game avail data of present node such that it is able to reduce the amount of analysis of present node income determination,
Improve analysis efficiency.
Depended in terms of intelligent grid compared to game theory in the prior art and use the security model of subjective parameters, this reality
Apply betting data analysis method and device disclosed in example, it is intended to formulate player's payment by objective utility function to alleviate this
Problem, the objective utility function can describe player behavior, they act generation influence and they on
Cost.
It should be understood by those skilled in the art that, embodiments of the invention can be provided as method, system or computer program
Product.Therefore, the present invention can be using the reality in terms of complete hardware embodiment, complete software embodiment or combination software and hardware
Apply the form of example.And, the present invention can be used and wherein include the computer of computer usable program code at one or more
The computer program implemented in usable storage medium (including but not limited to magnetic disk storage, CD-ROM, optical memory etc.) is produced
The form of product.
The present invention is the flow with reference to method according to embodiments of the present invention, equipment (system) and computer program product
Figure and/or block diagram are described.It should be understood that every first-class during flow chart and/or block diagram can be realized by computer program instructions
The combination of flow and/or square frame in journey and/or square frame and flow chart and/or block diagram.These computer programs can be provided
The processor of all-purpose computer, special-purpose computer, Embedded Processor or other programmable data processing devices is instructed to produce
A raw machine so that produced for reality by the instruction of computer or the computing device of other programmable data processing devices
The device of the function of being specified in present one flow of flow chart or multiple one square frame of flow and/or block diagram or multiple square frames.
These computer program instructions may be alternatively stored in can guide computer or other programmable data processing devices with spy
In determining the computer-readable memory that mode works so that instruction of the storage in the computer-readable memory is produced and include finger
Make the manufacture of device, the command device realize in one flow of flow chart or multiple one square frame of flow and/or block diagram or
The function of being specified in multiple square frames.
These computer program instructions can be also loaded into computer or other programmable data processing devices so that in meter
Series of operation steps is performed on calculation machine or other programmable devices to produce computer implemented treatment, so as in computer or
The instruction performed on other programmable devices is provided for realizing in one flow of flow chart or multiple flows and/or block diagram one
The step of function of being specified in individual square frame or multiple square frames.
Obviously, above-described embodiment is only intended to clearly illustrate example, and not to the restriction of implementation method.It is right
For those of ordinary skill in the art, can also make on the basis of the above description other multi-forms change or
Change.There is no need and unable to be exhaustive to all of implementation method.And the obvious change thus extended out or
Among changing still in the protection domain of the invention.