The unmanned aerial vehicles (UAVs) networks are very vulnerable to smart jammers that can choose their jamming strategy based on the ongoing channel state accordingly. Although reinforcement learning (RL) algorithms can give UAV networks the ability to make intelligent decisions, the high-dimensional state space makes it difficult for algorithms to converge quickly. This article proposes a knowledge-based RL method, which uses domain knowledge to compress the state space that the agent needs to explore and then improve the algorithm convergence speed. Specifically, we use the inertial law of the aircraft and the law of signal attenuation in free space to guide the highly efficient exploration of the UAVs in the state space. We incorporate the performance indicators of the receiver and the subjective value of the task into the design of the reward function, and build a virtual environment for pretraining to accelerate the convergence of anti-jamming decisions. In addition, the algorithm proposed is completely based on observable data, which is more realistic than those studies that assume the position or the channel strategy of the jammer. The simulation shows that the proposed algorithm can outperform the benchmarks of model-free RL algorithm in terms of converge speed and averaged reward.
随着人工智能技术向军事领域的渗透、融合、发展,未来战场的战争形态和作战样式将发生深刻变化,同时催生出一批与未来智能无人战场相适应的新型作战概念.从作战手段、作战空间和作战范式的角度分析未来战争的特点,重点综述了决策中心战、认知电子战和无人机集群作战三种新型作战概念,全面阐述了三种作战概念的提出的背景、内涵、演进以及作战理念,并对三种作战概念的发展趋势进行预测性分析,可为未来作战样式的研究、设计、论证提供重要参考.
针对军事信息网络的防御策略选取问题,分析军事信息网络的攻防对抗特点,提出一种军事信息网络主动防御策略选取方法.该方法基于不完全信息博弈对网络攻防过程进行建模,从网络安全属性的角度出发对攻防收益进行量化;以防御效能作为策略选取的标准,设计主动防御策略选取算法.与传统基于博弈论的网络防御方法相比,该方法具有如下优势:在模型设计和收益量化方面更加符合网络攻防实际;能够以纯策略的形式进行主动防御策略选取,有效解决当前以概率形式进行防御策略选取不便于理解和操作的问题.通过实验验证了所提方法的合理性和可行性,并通过防御收益分析总结了网络安全防御的一般规律.
针对现有被动防御方式难以有效确保军事信息网络安全的问题,从信号伪装的角度对军事信息网络的主动防御进行研究,提出了一种最优伪装信号选取方法.在分析军事信息网络攻防对抗的基础上,基于信号博弈理论对网络攻防过程进行建模;提出了网络攻防收益量化方法;在精炼贝叶斯纳什均衡分析的基础上,设计了最优伪装信号的选取算法.通过实验验证了方法的合理性和可行性,为军事信息网络安全防御提供了一种新的思路.
为了解决装备保障信息网络的安全防御问题,从信号伪装的角度对装备保障信息网络的主动防御进行研究,设计了一种最优伪装信号选取方法.该方法基于多阶段信号博弈理论对装备保障信息网络攻防过程进行建模;在考虑信号伪装成本的基础上对攻防收益进行量化;给出了精炼贝叶斯均衡的求解方法,并设计了多阶段最优伪装信号选取算法.通过实验对该方法的合理性和有效性进行验证,并分析总结了装备保障信息网络安全防御的一般规律.
The Unmanned Aerial Vehicles (UAV) networks consisting of low-cost UAVs are very vulnerable to smart jammers that can choose their jamming policies based on the ongoing communication policies accordingly.In this article, we propose a novel cloud and edge-aided mobile communication scheme for low-cost UAV network against smart jamming.The challenge of this problem is to design a communication scheme that not only meets the requirements of defending against smart jamming attack, but also can be deployed on low-cost UAV platforms.In addition, related studies neglect the problem of decision-making algorithm failure caused by intermittent ground-to-air communication.In this scheme, we use the policy network deployed on the cloud and edge servers to generate an emergency policy tables, and regularly update the generated policy table to the UAVs to solve the decision-making problem when communications are interrupted.In the operation of this communication scheme, UAVs need to offload massive computing tasks to the cloud or the edge servers.In order to prevent these computing tasks from being offloaded to a single computing resource, we deployed a lightweight game algorithm to ensure that the three types of computing resources, namely local, edge and cloud, can maximize their effectiveness.The simulation results show that our communication scheme has only a small decrease in the SINR of UAVs network in the case of momentary communication interruption, and the SINR performance of our algorithm is higher than that of the original Q-learning algorithm.
为了能实时准确地评估网络安全风险,提出一种基于隐马尔科夫模型的网络安全风险评估方法.该方法基于隐马尔科夫模型对目标网络进行建模,通过节点的直接风险和相关性引起的间接风险来量化节点的安全风险;考虑节点在网络中的重要性程度,结合节点安全风险,量化目标网络的整体安全风险.通过实验对所提方法进行验证.实验结果表明:该方法能够对由节点相关性和节点重要性程度所带来的网络安全风险进行量化,使得网络安全风险评估结果更加准确、可信.与传统的网络安全风险评估方法相比,该方法能够更加及时地发现网络中的异常风险变化情况,为网络安全防御策略的及时调整提供依据.
针对当前部分传统身份认证技术存在耗能高、计算量大、效率低等缺陷,提出一种基于近场通信(Near Field Communication, NFC)技术的一次性口令认证方案。该方案不仅具有一次性口令成本较低、实现简单的优点,适用于物联网环境;同时通信双方运用NFC技术进行交互,利用NFC设备初始化时进行的冲突检测有效地解决了一次性口令认证明文传输的安全性问题。通过对其进行分析,可知该方案在有效防止常见攻击的同时保证了较小的计算量和较高的效率,能够应用到物联网环境中。
Unmanned aerial vehicle (UAV) networks have a wide range of applications, such as in the Internet of Things (IoT), 5G communications, and so forth. However, the communications between UAVs and UAVs to ground control stations mainly use radio channels, and therefore these communications are vulnerable to cyberattacks. With the advent of software-defined radio (SDR), smart attacks that can flexibly select attack strategies according to the defender’s state information are gradually attracting the attention of researchers and potential attackers of UAV networks. The smart attack can even induce the defender to take a specific defense strategy, causing even greater damage. Inspired by symmetrical thinking, a solution using a software-defined network (SDN) to combat software-defined radio was proposed. We propose a network architecture which uses dual controllers, including a UAV flight controller and SDN controller, to achieve collaborative decision-making. Built on the top of the SDN, the state information of the whole network converges quickly and is fitted to an environment model used to develop an improved Dyna-Q-based reinforcement learning algorithm. The improved algorithm integrates the power allocation and track planning of UAVs into a unified action space. The simulation data showed that the proposed communication solution can effectively avoid smart jamming attacks and has faster learning efficiency and higher convergence performance than the compared algorithms.
Existing passive defence methods cannot effectively guarantee network security; to solve this problem, a novel method is proposed that selects the optimal defence strategy. The network attack-defence process is modelled based on the Bayesian game. The payoff is quantified from the impact value of the attack-defence actions. The optimal defence strategy is selected that takes defence effectiveness as the criterion. The rationality and feasibility of the method are verified through a representative example, and the general rules of network defence are summarised. Compared to the classic strategy selection methods based on game theory, the proposed method can select the optimal strategy in the form of pure strategy by quantifying defence effectiveness, which was proven to perform better.
针对现有基于博弈理论的网络防御策略选取方法没有考虑攻防双方策略选取能力差异对博弈过程的影响和以概率的形式给出最优防御策略导致可操作性不强的问题,提出了一种基于静态贝叶斯博弈的最优防御策略选取方法.该方法从不完全信息角度对网络攻防过程进行建模;通过收敛度对攻防双方策略选取能力的差异进行量化;在对混合策略贝叶斯纳什均衡分析的基础上,对防御效能进行量化;以防御效能为标准进行最优防御策略的选取.通过实例分析验证了所提方法的合理性和可行性.与传统基于博弈理论的策略选取方法相比,该方法更加紧贴网络实际,具有更强的可操作性.
为了准确评估军事信息网络的安全风险,提高网络的安全性,提出了基于攻防博弈的网络安全风险评估方法.首先,根据军事信息网络攻防的特点,设计了网络攻防博弈模型,从网络安全属性的角度出发量化攻防策略收益,并对攻防博弈混合策略的纳什均衡进行分析;其次,分析了基于攻防博弈进行网络安全风险评估的可行性,并设计了基于攻防博弈的网络安全风险评估算法;最后,通过实验分析验证了方法的合理性和可行性.
为了提高战场通信网络的安全性,基于北斗卫星导航系统(“BeiDou”navigation satellitesystem,BDS)所提供的高质量的定位、授时以及短报文通信功能,提出了一种基于“北斗”的战场通信网络身份认证方案.该方案利用“北斗”高精度的授时功能实现整个网络中时钟的精确同步,将该时钟信息作为时间戳值加入到身份认证过程中以抵抗重放攻击;同时将节点从“北斗”获得的位置信息也加入到身份认证信息中,解决了战场中我方节点被俘获所带来的安全问题,结合传统的随机数以及证书加密,实现了通信双方多因素双向认证.通过对方案进行安全性分析和SVO逻辑分析可知,该方案能够抵抗常见的攻击方式,并且不存在安全漏洞,适合应用到战场通信网络.
网络安全风险评估为准确评估网络的安全状态提供依据,是构建网络安全体系的基础和前提.在对网络安全风险评估进行概述的基础上,介绍了目前主流的网络安全风险评估方法,分析了其各自的优缺点,并对网络安全风险评估的发展趋势做出了预测.
A construction plan of equipment support information network in cloud environment is put forward in view of the current situation that the equipment support network can not meet the needs of equipment support business in the modern war. Starting from the demand of equipment support information network and the goal of equipment support, the basic architecture and detailed construction method of equipment support information network under the cloud environment are proposed based on the flexible and efficient features of cloud computing. This scheme will provide technical support for the information equipment support of our army.
当前网站采用HTTPS协议加密,对其实施监管与审查仅能识别站点,而不能进一步精细化识别子页面,针对这一问题,提出了一种针对HTTPS协议加密站点在使用内容分发网络(Content Distribute Network,CDN)分发资源情况下的精细化指纹攻击方法.首先利用CDN分发过程中将用户重定向到就近镜像服务器产生的域名系统(Domain Name System,DNS)查询序列作为页面指纹,然后使用支持向量机(Support Vector Machine,SVM)模型进行页面识别,最后采用在Internet中收集的数据集进行验证.结果表明:该方法获得了93%的站点子页面识别率,能有效精细化识别HTTPS加密站点的子页面.
Aiming at extracting traffic features using manual selection and feature combination methods in current network traffic feature engineering, it is difficult to accurately extract the features of common traffic characteristics. A network traffic feature extraction method based on autoencoder model is proposed. The method first converts the first 144 bytes of the network data packet into a numeric code, and then acts as an input to the stacked autoencoder, then outputs a 49-dimensional feature through a 4-layer network encode. Using the dataset collected in laboratory to verify the method, experiments show that the feature extracted by this method can effectively extract network traffic characteristics, the extracted features are representative, and can use low-dimensional data to represent high-dimensional data.
In view of the increasing network information security problem, from the perspective of transmission layer security, an interactive scheme of OpenSSL (Open Secure Sockets Layer) and CSP (Cryptographic Service Provider) based on virtual private key is proposed, and the security and rationality of interaction part is analyzed by means of the formal analysis of logic language. After registering the private key for the first time, the scheme strictly follows the requirement that the private key can't be out of the device. With the design of a virtual private key, the virtual private key is used all at the moment when the private key needs to be transmitted, so as to avoid generating a copy of the real private key, to ensure the uniqueness of a real private key and improve the security. In the meantime, the scheme saves the virtual private key in OpenSSL and the real private key in CSP. That is the method of "saving the private key both securely", minimizing changes to OpenSSL. The smaller workload can not only effectively reduce the risk of loopholes but also improve the versatility of the program.
A network security risk assessment method based on node correlation is proposed in order to solve the problem that little consideration is given to node correlation and diversity in tradition network security risk assessments. This method which is based on Hidden Markov model quantifies security risk of the node through indirect risks caused by the direct risks and correlations of nodes. Combined the security risk and the importance of the node, the overall risk of the target network is calculated. This method can evaluate network security risk more accurately and provide basis for the formulation of network security policy.
针对当前基于攻击图的网络安全风险评估方法在评估过程中考虑网络实际运行情况不全面的问题,提出了一种基于贝叶斯攻击图的网络安全风险评估方法.首先,基于贝叶斯攻击图对目标网络进行了建模;其次,结合攻击意图和原子攻击的特性,利用先验概率对属性节点的静态风险进行了评估;最后,运用贝叶斯推理方法中的后验概率对静态风险评估攻击图进行了动态更新,实现了对目标网络的动态风险评估.通过试验分析验证了该方法的可行性,可为实施网络安全防护策略提供依据.