信息网络安全 ›› 2026, Vol. 26 ›› Issue (1): 59-68.doi: 10.3969/j.issn.1671-1122.2026.01.005

• 专题论文:网络主动防御 • 上一篇    下一篇

基于动态安全管理模式的信息系统安全防御策略研究

吴越1, 张雅雯2, 程相然1,3()   

  1. 1.网络空间部队信息工程大学密码工程学院,郑州 450001
    2.中国人民解放军92330部队,青岛 266100
    3.复旦大学网络空间国际治理研究基地,上海 200433
  • 收稿日期:2025-03-30 出版日期:2026-01-10 发布日期:2026-02-13
  • 通讯作者: 程相然 hongshan643@163.com
  • 作者简介:吴越(1996—),男,浙江,硕士研究生,主要研究方向为网络安全管理、网络危机管理|张雅雯(1996—),女,山东,硕士,主要研究方向为网络安全管理、网络入侵检测|程相然(1984—),男,河南,讲师,博士,主要研究方向为网络安全管理、网络防御

Research on Security Defense Strategy of Information System Based on Dynamic Security Management Model

WU Yue1, ZHANG Yawen2, CHENG Xiangran1,3()   

  1. 1. School of Cryptographic Engineering, Cyberspace Force Information Engineering University, Zhengzhou 450001, China
    2. Unit 92330 of PLA, Qingdao 266100, China
    3. Cyberspace International Governance Research Base, Fudan University, Shanghai 200433, China
  • Received:2025-03-30 Online:2026-01-10 Published:2026-02-13

摘要:

针对静态安全管理模式应对动态安全管理场景的局限,考虑攻防对抗行为对策略选择的影响,文章提出基于动态安全管理模式的信息系统安全防御策略选择方法。该方法融合信念理论,构建信念随机博弈模型,有效模拟信息系统在面对不同安全威胁时的信念状态和攻防过程。通过分析两者之间的博弈关系,评估系统的安全状态,计算攻防状态下管理者的防御成本和收益,进而得出攻击成功率,从而确定最优防御策略。该实验以真实涉密信息系统为研究对象,从攻击成功率、防御成本和防御收益3个方面验证该方法的有效性,为信息系统的安全管理提供科学依据和改进意见。

关键词: 信息系统安全, 动态管理模式, 精炼贝叶斯, 信念理论

Abstract:

Aiming at the limitation of static security management mode in dealing with dynamic security management scenarios, considering the influence of offensive and defensive confrontation behavior on strategy selection, this paper put forward a security defense strategy selection method of information system based on dynamic security management mode. Combining belief theory, a belief random game model was constructed to effectively simulate the belief state and the attack and defense process of information systems in the face of different security threats. By analyzing the game relationship between them, the security state of the system was evaluated, and the defense costs and benefits of managers in the attack and defense state were calculated, as well as the impact on the success rate of attacks, so as to the optimal defense strategy. Taking the real classified information system as the research object, this paper demonstrated the effectiveness of the experiment from three aspects: attack success rate, defense cost and defense benefit, which provides scientific basis and improvement suggestions for the security management of information system.

Key words: information system security, dynamic management model, refined Bayesian, belief theory

中图分类号: