信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 967-976.doi: 10.3969/j.issn.1671-1122.2026.06.010
谢晓敏1,2,3, 李鹏燈1,2,3, 刘园1,2,3(
), 田志宏1,2,3
收稿日期:2025-06-12
出版日期:2026-06-10
发布日期:2026-07-27
通讯作者:
刘园
E-mail:yuanliu@gzhu.edu.cn
作者简介:谢晓敏(2000—),女,广东,博士研究生,主要研究方向为网络空间资产测绘与抗测绘、主动防御|李鹏燈(1992—),男,广东,副教授,博士,CCF会员,主要研究方向为网络空间安全、博弈论、人工智能|刘园(1986—),女,广东,教授,博士,CCF杰出会员,主要研究方向为网络安全、数据安全、区块链安全|田志宏(1978—),男,广东,教授,博士,CCF杰出会员,主要研究方向为网络安全、系统安全、工控安全
基金资助:
XIE Xiaomin1,2,3, LI Pengdeng1,2,3, LIU Yuan1,2,3(
), TIAN Zhihong1,2,3
Received:2025-06-12
Online:2026-06-10
Published:2026-07-27
Contact:
LIU Yuan
E-mail:yuanliu@gzhu.edu.cn
摘要:
在网络空间资产测绘与抗测绘领域,攻击者大多采用广度优先分批扫描策略探测在线活跃主机,进而筛选潜在攻击目标。防御者主要通过设定网络流量阈值,实现恶意扫描行为的检测识别。然而,网络环境具备动态多变特征,且攻击者可灵活调整扫描策略,导致传统静态防御策略的动态适配能力存在明显短板。为解决该问题,文章构建一种面向主机扫描与抗扫描的随机博弈模型,将连续分组扫描过程转化为马尔可夫决策过程,精准刻画攻防双方动态策略的演化机制,并采用改进非对称纳什学习算法求解近似均衡解。实验结果表明,在均衡条件下,文章所提动态策略的综合收益显著优于传统固定策略。
中图分类号:
谢晓敏, 李鹏燈, 刘园, 田志宏. 一种面向主机扫描与抗扫描的随机博弈模型[J]. 信息网络安全, 2026, 26(6): 967-976.
XIE Xiaomin, LI Pengdeng, LIU Yuan, TIAN Zhihong. A Stochastic Game Model for Host Scanning and Anti-Scanning[J]. Netinfo Security, 2026, 26(6): 967-976.
表1
相关符号对应的元素定义
| 符号 | 定义 |
|---|---|
| N | 目标主机范围内主机总数 |
| n | 攻击者当前已扫描主机数量 |
| m | 防御者将合法源地址误报为恶意扫描地址的数量 |
| τ | 扫描一组主机所需的时间 |
| t | 第t个时间步(表示博弈时间进程) |
| G | 分组总数 |
| T | 扫描全部主机所需的总时间步 |
| | 各阶段博弈对抗的状态 |
| | 参与者i的行动 |
| | 参与者i遵循均衡策略 |
| | 博弈状态中,扫描行为被检测成功的标识 |
| | 参与者i的收益函数 |
| | 参与者i的折扣因子(表示耐心程度) |
| | 参与者i的收益函数 |
| | 参与者i的策略 |
| | 参与者i的策略空间 |
| | 第i个主机分组的编号 |
| | 第i个主机分组中包含的主机数量 |
| | 参与者i的最优均衡策略 |
| [1] | ZOU Zhenwan, HOU Yingsa, GUO Qingrui. Research on Cyberspace Surveying and Mapping Technology Based on Asset Detection[C]// IEEE. 2024 IEEE 6th Advanced Information Management, Communicates, Electronic and Automation Control Conference (IMCEC). New York: IEEE, 2024: 946-949. |
| [2] | XUE Xiangyang, ZOU Hong, ZHAO Jin, et al. Advances in Anti-Surveying-and-Mapping Theory and Technologies for Data Infrastructure[J]. Strategic Study of CAE, 2025, 27(1): 72-87. |
| 薛向阳, 邹宏, 赵进, 等. 数据基础设施抗测绘理论与技术发展研究[J]. 中国工程科学, 2025, 27(1): 72-87. | |
| [3] | DURUMERIC Z, BAILEY M, HALDERMAN J A. An {Internet-Wide} View of {Internet-Wide} Scanning[C]// USENIX. The 23rd USENIX Conference on Security Symposium. Berkeley: USENIX, 2014: 65-78. |
| [4] | SHENG Chuan, YAO Yu, ZHAO Lianxiang, et al. Scanner-Hunter: An Effective ICS Scanning Group Identification System[J]. IEEE Transactions on Information Forensics and Security, 2024, 19: 3077-3092. |
| [5] | CASWELL B, FOSTER J C, RUSSELL R, et al. Snort 2.0 Intrusion Detection[M]. Rockland: Syngress Publishing, 2003. |
| [6] | SHAPLEY L S. Stochastic Games[J]. Proceedings of the National Academy of Sciences of the United States of America (PNAS), 1953, 39(10): 1095-1100. |
| [7] | BITIRGEN K, FILIK U B. Markov Game Based on Reinforcement Learning Solution against Cyber-Physical Attacks in Smart Grid[EB/OL]. (2024-12-01)[2025-05-13]. https://www.sciencedirect.com/science/article/abs/pii/S095741742401474X |
| [8] | HU Junling, WELLMAN M P. Nash Q-Learning for General-Sum Stochastic Games[J]. Journal of Machine Learning Research, 2003(4): 1039-1069. |
| [9] | LEONARD D, LOGUINOV D. Demystifying Service Discovery: Implementing an Internet-Wide Scanner[C]// ACM. The 10th ACM SIGCOMM Conference on Internet Measurement. New York: ACM, 2010: 109-122. |
| [10] | LEONARD D, YAO Zhongmei, WANG Xiaoming, et al. Stochastic Analysis of Horizontal IP Scanning[C]// IEEE. 2012 Proceedings IEEE INFOCOM. New York: IEEE, 2012: 2077-2085. |
| [11] | ALI M Q, AL-SHAER E, SAMAK T. Firewall Policy Reconnaissance: Techniques and Analysis[J]. IEEE Transactions on Information Forensics and Security, 2014, 9(2): 296-308. |
| [12] | LEE C B, ROEDEL C, SILENOK E. Detection and Characterization of Port Scan Attacks[EB/OL]. (2003-06-18)[2025-05-13]. https://www.semanticscholar.org/paper/Detection-and-Characterization-of-Port-Scan-Attacks-Lee-Roedel/8830f1780bd7da10fd6090346b83d17fc9b09c97 |
| [13] | RICHTER P, SMARAGDAKIS G, PLONKA D, et al. Beyond Counting: New Perspectives on the Active IPv4 Address Space[C]// ACM. The 2016 Internet Measurement Conference. New York: ACM, 2016: 135-149. |
| [14] | STANIFORD S, PAXSON V, WEAVER N. How to Own the Internet in Your Spare Time[EB/OL]. (2002-08-05)[2025-05-13]. https://www.researchgate.net/publication/238280597_Nicholas_Weaver_How_to_0wn_the_Internet_in_Your_Spare_Time |
| [15] | WANG Pinghui, ZHENG Qinghua, NIU Guolin, et al. Port Scan Detection Algorithms Based on Statistical Traffic Features[J]. Journal on Communications, 2007(12): 14-18. |
| 王平辉, 郑庆华, 牛国林, 等. 基于流量统计特征的端口扫描检测算法[J]. 通信学报, 2007(12): 14-18. | |
| [16] | SAGATOV E S, MAYHOUB S, SUKHOV A M, et al. Proactive Detection for Countermeasures on Port Scanning Based Attacks[C]// IEEE. 2021 17th International Conference on Network and Service Management (CNSM). New York: IEEE, 2021: 402-406. |
| [17] | AFFINITO A, BOTTA A, GALLO L, et al. Spark-Based Port and Net Scan Detection[C]// ACM. The 35th Annual ACM Symposium on Applied Computing. New York: ACM, 2020: 1172-1179. |
| [18] | PATEL S K, SONKER A. Rule-Based Network Intrusion Detection System for Port Scanning with Efficient Port Scan Detection Rules Using Snort[J]. International Journal of Future Generation Communication and Networking, 2016, 9(6): 339-350. |
| [19] | VUGRIN E D, CRUZ J, REEDY C, et al. Cyber Threat Modeling and Validation: Port Scanning and Detection[C]//ACM. The 7th Symposium on Hot Topics in the Science of Security. New York: ACM, 2020: 1-10. |
| [20] | KIKUCHI H, FUKUNO N, KOBORI T, et al. Automated Port-Scan Classification with Decision Tree and Distributed Sensors[J]. Journal of Information Processing, 2008, 16: 165-175. |
| [21] | BOUKEBOUS A A E, FETTACHE M I, BENDIAB G, et al. A Comparative Analysis of Snort3 and Suricata[C]// IEEE. 2023 IEEE IAS Global Conference on Emerging Technologies (GlobConET). New York: IEEE, 2023: 1-6. |
| [22] | NING Zepeng, XIE Lihua. A Survey on Multi-Agent Reinforcement Learning and Its Application[J]. Journal of Automation and Intelligence, 2024, 3(2): 73-91. |
| [23] | MOGHADDAM A R, KEBRIAEI H. Multiagent Reinforcement Learning for Nash Equilibrium Seeking in General-Sum Markov Games[J]. IEEE Transactions on Systems, Man, and Cybernetics: Systems, 2025, 55(1): 221-227. |
| [24] | HU Jueming, PALIWAL Y, KIM H, et al. Reinforcement Learning with Predefined and Inferred Reward Machines in Stochastic Games[EB/OL]. (2024-09-28)[2025-05-13]. https://www.sciencedirect.com/science/article/abs/pii/S092523122400941X |
| [1] | 王钢, 高雲鹏, 杨松儒, 孙立涛, 刘乃维. 基于深度学习的加密恶意流量检测方法研究综述[J]. 信息网络安全, 2025, 25(8): 1276-1301. |
| [2] | 孙剑文, 张斌, 司念文, 樊莹. 基于知识蒸馏的轻量化恶意流量检测方法[J]. 信息网络安全, 2025, 25(6): 859-871. |
| [3] | 耿致远, 许泽轩, 张恒巍. 基于随机博弈和DQN算法的云原生移动目标防御决策方法[J]. 信息网络安全, 2025, 25(6): 967-976. |
| [4] | 郭钰铮, 郭春, 崔允贺, 李显超. 基于随机博弈网的窃密木马诱导式博弈模型[J]. 信息网络安全, 2024, 24(8): 1241-1251. |
| [5] | 李志华, 陈亮, 卢徐霖, 方朝晖, 钱军浩. 面向物联网Mirai僵尸网络的轻量级检测方法[J]. 信息网络安全, 2024, 24(5): 667-681. |
| [6] | 顾国民, 陈文浩, 黄伟达. 一种基于多模型融合的隐蔽隧道和加密恶意流量检测方法[J]. 信息网络安全, 2024, 24(5): 694-708. |
| [7] | 屠晓涵, 张传浩, 刘孟然. 恶意流量检测模型设计与实现[J]. 信息网络安全, 2024, 24(4): 520-533. |
| [8] | 张强, 何俊江, 李汶珊, 李涛. 基于深度度量学习的异常流量检测方法[J]. 信息网络安全, 2024, 24(3): 462-472. |
| [9] | 张志强, 暴亚东. 融合RF和CNN的异常流量检测算法[J]. 信息网络安全, 2024, 24(11): 1655-1664. |
| [10] | 胡文涛, 徐靖凯, 丁伟杰. 基于溯因学习的无监督网络流量异常检测[J]. 信息网络安全, 2024, 24(11): 1675-1684. |
| [11] | 刘宇啸, 陈伟, 张天月, 吴礼发. 基于稀疏自动编码器的可解释性异常流量检测[J]. 信息网络安全, 2023, 23(7): 74-85. |
| [12] | 刘奕, 李建华, 张一瑫, 孟涛. 基于特征属性信息熵的网络异常流量检测方法[J]. 信息网络安全, 2021, 21(2): 78-86. |
| [13] | 张浩, 陈龙, 魏志强. 基于数据增强和模型更新的异常流量检测技术[J]. 信息网络安全, 2020, 20(2): 66-74. |
| [14] | 陈冠衡, 苏金树. 基于深度神经网络的异常流量检测算法[J]. 信息网络安全, 2019, 19(6): 68-75. |
| [15] | 朱毅, 陈兴蜀, 陈敬涵, 邵国林. 基于模糊综合评价模型的DNS健康度评估[J]. 信息网络安全, 2018, 18(4): 65-71. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||