基于博弈的电力工控网络APT攻击溯源图分析方法OA
A Game Theory-based Approach for APT Attack Provenance Graph Analysis in Electric Power Industrial Control Networks
在电力工控网络安全中,高级持续性威胁(advanced persistent threat,APT)攻击具有隐蔽性强、持续性长的特点,而现有利用图神经网络对溯源图中的子图进行匹配和分析,以判断是否存在恶意攻击行为的APT攻击检测手段,存在子图识别窗口大小不当,从而影响检测效果的问题.为此,提出一种基于Stackelberg博弈的动态子图识别窗口调整机制.该机制通过构建防守者与攻击者的效用函数模型,以博弈方式动态优化识别窗口大小:防守者作为博弈领导者,选择窗口大小以提高检测成功率并降低检测成本;攻击者则根据防守策略调整APT子图规模以逃避检测.博弈求解得到防守者的最优窗口调整策略及攻击者的响应策略.仿真结果表明,该机制相比固定窗口方法,检测准确率平均提升约16%,计算资源效率提高约25%,有效降低了漏报率和误报率.
Advanced persistent threat(APT)attacks electric power industrial control networks exhibit strong concealment and long-term persistence.However,existing APT detection methods relaying on graph neural networks to match and analyze subgraphs within provenance graphs for malicious behavior identification often suffers from suboptimal subgraph recognition window sizes,which degrades detection performance.To address this,a dynamic subgraph recognition window adjustment mechanism based on the Stackelberg game is proposed.This mechanism constructs utility function models for both the defender and the attacker,dynamically optimizing the recognition window size in a game theory approach.In which the defender,as the game leader,optimizes the window size to improve the detection success rate and reduce detection costs.The attacker,on the other hand,adjusts the scale of the APT subgraph according to the defense strategy to evade detection.The game solution yields the optimal window adjustment strategy for the defender and the response strategy for the attacker.Simulation results indicate that,compared to the fixed window method,this mechanism improves detection accuracy by approximately 16%on average,enhances computational resource efficiency by about 25%,and effectively reduces both false negatives and false positives.
刘新;王睿;张朋丰;张昊;刘涵
国网山东省电力公司电力科学研究院,山东 济南 250003||山东省能源工业互联网大数据技术重点实验室,山东 济南 250003国网山东省电力公司电力科学研究院,山东 济南 250003||山东省能源工业互联网大数据技术重点实验室,山东 济南 250003国网山东省电力公司,山东 济南 250001国网山东省电力公司电力科学研究院,山东 济南 250003||山东省能源工业互联网大数据技术重点实验室,山东 济南 250003西安交通大学网络空间安全学院,陕西 西安 710049
信息技术与安全科学
APT攻击溯源图子图识别电力工控网络Stackelberg博弈
APT attackprovenance graphsubgraph recognitionelectric power industrial control networksStackelberg game
《山东电力技术》 2026 (4)
87-96,10
国网山东省电力公司科技项目"跨区跨界隐蔽攻击检测与防护技术研究项目"(520626230019). Science and Technology Project of State Grid Shandong Electric Power Company"Research on Detection and Protection Technologies for Cross-Regional and Cross-Domain Stealth Attacks"(520626230019).
评论