arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从安全事件到冲突状态:用于增强网络态势感知的三层网络防御场景模型

From Security Events to Conflict States: A Three-layer Cyber Defense Scenario Model for Enhanced Cyber Situational Awareness

Miguel Requena Micó, Mario Fernandez-Tarraga, Daniel Díaz-López, Sergio López Bernal, Gregorio Martínez Pérez

arXiv 2608.27215首次发表:更新:

AI 中文总结

本文提出一种面向任务的网络防御框架,基于三层集成概率模型与NetLogo仿真原型,可增强网络态势感知,经多维度评估验证其能实现攻击进程、不确定性管理等环节的连贯关联。

AI 中文摘要

关键任务环境中的网络防御需要集成方法,能够在统一框架内表示对抗进程、防御方不确定性、任务影响以及防御决策支持。在作战领域,防御方必须在不完整且含噪声的观测下,持续估计不断演变的安全态势,同时保障关键任务功能的连续性与完整性。本文提出一种面向任务的网络防御框架,用于网络态势感知(CSA)与决策支持,该框架基于三层集成概率模型与可执行仿真原型构建。模型整合了:(i)攻击图模型,用于表示对抗方通过与任务相关资产的可能进程;(ii)事件模型,通过贝叶斯推理将观测遥测数据转换为防御方的后验信念;(iii)状态模型,将推断出的态势抽象为冲突状态与任务风险等级。这些组件与一步防御行动规则相连,该规则平衡了估计的残余任务风险与操作成本。该框架在NetLogo代理基仿真中实例化,仿真环境结构涵盖战术边缘区(TEZ)、任务操作区(MOZ)与企业支持区(ESZ)。提案通过数学一致性分析、遥测扰动下的局部鲁棒性评估以及代表性仿真轨迹进行评估。结果表明,该框架及其实现保留了攻击进程、遥测驱动的不确定性管理、任务影响评估以及以任务风险优先级为导向的成本感知防御决策支持之间的连贯关系。

英文摘要

Cyber defense in mission-critical environments requires integrated approaches capable of representing adversarial progression, defender-side uncertainty, mission impact, and defensive decision support within a unified framework. In operational domains, defenders must continuously estimate the evolving security posture while preserving the continuity and integrity of mission-critical functions under incomplete and noisy observations. This paper presents a mission-oriented cyber-defense framework for Cyber Situational Awareness (CSA) and decision support based on a three-layer integrated probabilistic model and an executable simulation prototype. The model combines: (i) an attack-graph model that represents possible adversarial progression through mission-relevant assets, (ii) an event model that transforms observed telemetry into posterior defender beliefs through Bayesian inference, and (iii) a state model that abstracts the inferred posture into conflict states and mission-risk levels. These components are connected to a one-step defensive action rule that balances estimated residual mission risk and operational cost. The framework is instantiated in a NetLogo agent-based simulation of an operational environment structured across the Tactical Edge Zone (TEZ), Mission Operations Zone (MOZ), and Enterprise Support Zone (ESZ). The proposal is assessed through mathematical consistency analysis, local robustness assessment under telemetry perturbations, and representative simulation traces. Results indicate that the framework and its implementation preserve coherent relationships between attack progression, telemetry-driven uncertainty management, mission-impact assessment, and cost-aware defensive decision support guided by mission-risk prioritization.

Comments18 pages, 3 figures, 1 table, paper in proceedings of The International Conference on Availability, Reliability and Security, ARES 2026 in Linkoping, Sweden, August 24-27, 2026

DOI:10.1007/978-3-032-35579-9_20

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑