信息网络安全 ›› 2024, Vol. 24 ›› Issue (8): 1241-1251.doi: 10.3969/j.issn.1671-1122.2024.08.010

郭钰铮1,2, 郭春1,2(), 崔允贺1,2, 李显超1   

  1. 1.贵州大学计算机科学与技术学院,贵阳 550025
    2.文本计算与认知智能教育部工程研究中心,贵阳 550025
  • 收稿日期:2024-05-13 出版日期:2024-08-10 发布日期:2024-08-22
  • 通讯作者: 郭春
  • 作者简介:郭钰铮(2000—),女,河南,硕士研究生,CCF学生会员,主要研究方向为恶意软件分析|郭春(1986—),男,贵州,教授,博士,CCF高级会员,主要研究方向为恶意软件分析、入侵检测和数据挖掘|崔允贺(1987—),男,山东,副教授,博士,CCF专业会员,主要研究方向为软件定义网络、边缘计算和云计算|李显超(1979—),男,河南,硕士,主要研究方向为数据中心、物联网和云计算
  • 基金资助:
    国家自然科学基金(62162009);国家自然科学基金(62102111);贵州省高等学校大数据与网络安全创新团队(黔教技[2023]052);贵州省科技计划项目(黔科合平台人才 GHB[2023]001)

Inducement Game Model of Data-Stealing Trojan Based on Stochastic Game Nets

GUO Yuzheng1,2, GUO Chun1,2(), CUI Yunhe1,2, LI Xianchao1   

  1. 1. College of Computer Science and Technology, Guizhou University, Guiyang 550025, China
    2. Engineering Research Center for Text Computing and Cognitive Intelligence, Ministry of Education, Guiyang 550025, China
  • Received:2024-05-13 Online:2024-08-10 Published:2024-08-22



关键词: 窃密木马, 博弈模型, 诱导操作, 随机博弈网


To achieve the long-term goal of information theft, data-stealing Trojans typically employ the trigger execution strategy, providing high concealment and uncertainty in the execution of their malicious actions. The mainstream defense model against data-stealing Trojans adopts a passive defense strategy that involves monitoring and detecting the behavior of these Trojans, but is prone to omissions and delayed detection. To improve the defense effectiveness, this paper introduced the concept of inducement operation to construct an inducement-based defense strategy targeting data-stealing Trojans. Using stochastic game nets, this paper modeled and analyzed the confrontation process between the data-stealing Trojans and defenders, resulting in the development of the Inducement Game Model of Data-Stealing Trojan (IGMDT-SGN). IGMDT-SGN provides a clear illustration of the strategic logic and temporal dynamics of employing the inducement defense strategy against these Trojans. Quantitative analysis conducted through model calculations shows that the inducement defense strategy, as presented in IGMDT-SGN, outperforms the passive defense strategy in terms of defense success rate and average defense time. This finding provides useful guidance for defending against data-stealing Trojans.

Key words: data-stealing Trojan, game model, inducement operation, stochastic game nets
