计算机科学 ›› 2026, Vol. 53 ›› Issue (7): 414-421.doi: 10.11896/jsjkx.250500059

• 信息安全 • 上一篇    下一篇

基于异常感知的多变量拟态裁决算法

王佳, 甘永强   

  1. 新疆大学计算机科学与技术学院 乌鲁木齐 830000
  • 收稿日期:2025-05-15 修回日期:2025-08-15 出版日期:2026-07-15 发布日期:2026-07-10
  • 通讯作者: 甘永强(107552403897@stu.xju.edu.cn)
  • 作者简介:(jw1024@xju.edu.cn)
  • 基金资助:
    新疆维吾尔自治区重点研发计划(2022B01008);国家自然科学基金(62363032);新疆维吾尔自治区自然科学基金(2023D01C20);新一代人工智能国家科技重大专项(2022ZD0115803);“天池博士”计划(202104120018)

Multivariate Mimic Voting Method Based on Anomaly Perception

WANG Jia, GAN Yongqiang   

  1. School of Computer Science and Technology,Xinjiang University,Urumqi 830000,China
  • Received:2025-05-15 Revised:2025-08-15 Published:2026-07-15 Online:2026-07-10
  • About author:WANG Jia,born in 1987,Ph.D,asso-ciate professor,is a member of CCF(No.K8521M).Her main research interests include resource allocation in clouds,tasks scheduling in big data and cyberspace security.
    GAN Yongqiang,born in 2001,postgraduate.His main research interests include cyberspace security and mimic defense.
  • Supported by:
    Key R&D Program of Xinjiang Uygur Autonomous Region(2022B01008),National Natural Science Foundation of China(62363032),Natural Science Foundation of Xinjiang Uygur Autonomous Region(2023D01C20),National Science and Technology Major Project(2022ZD0115803) and “Heaven Lake Doctor” Project(202104120018).

摘要: 在拟态防御系统中,裁决器的安全性会直接影响系统对网络攻击的防御能力。现有的拟态裁决算法通常仅借助异常检测来提升对执行体错误输出的感知能力,或仅依赖于异构度/历史置信度来量化执行体输出的可靠性,导致算法在动态网络环境中面对复合攻击时无法准确评估高阶共模漏洞对裁决结果的影响,最终造成裁决错误。为了应对动态网络环境下高阶共模漏洞引起的系统失效问题,提出基于异常感知的多变量拟态裁决算法。针对裁决使用的异常检测模型仅关注时序或空间信息的问题,构建时空异常感知模型来更加精准地捕获执行体输出数据的异常时空特征;同时,针对高阶共模漏洞和执行体自身结构原因导致的裁决误判问题,引入高阶异构度和历史置信度,并结合数据一致度来提高裁决结果的可靠性。最终,通过动态权重调整策略自适应优化指标权重来输出最优加权结果。实验结果表明,所提算法在CICIDS和UNSW-NB15数据集上的平均准确率达到了98.77%,尤其在UNSW-NB15上表现更为明显,相较于传统算法平均提升2%左右,具有良好的稳定性和泛化能力,能较好地满足拟态系统的实际需求。

关键词: 拟态防御, 裁决算法, 异常检测, 高阶异构度, 历史置信度

Abstract: In mimic defense system,the security of mimic voter directly affects the system defensive capability.Existing mimic voting algorithms typically either rely on anomaly detection to enhance the perception of error outputs of executors,or depend on heterogeneity or historical confidence to quantify the reliability of executor outputs,which leads to inexact voting output with higher-order common-mode vulnerabilities in dynamic network environments.To address above problem,this paper proposes a multivariable mimic voting based on anomaly perception.Because existing anomaly detection models always focuse on temporal or spatial information,a spatiotemporal anomaly perception model is constructed to more precisely capture the spatiotemporal cha-racteristics of executor output.Simultaneously,with the consideration of decision misjudgment caused by higher-order common-mode vulnerabilities and structural reasons of executors,higher-order heterogeneity and historical confidence are integrated with data consistency to improve the reliability of the voting results.Ultimately,an adaptive optimization strategy is desigened to adjust weight metrics to yield the optimal weighted outcome.Experimental results show that the proposed algorithm achieves an average accuracy of 98.77% on CICIDS and UNSW-NB15 datasets.Especially,a significant improvement of average about 2% over traditional algorithms on UNSW-NB15,demonstrating better stability and generalizability.

Key words: Mimic defense, Voting algorithm, Anomaly detection, Higher-order heterogeneity, Historical confidence

中图分类号: 

  • TP393.08
[1]PETER O,PRADHAN A,MBOHWA C.Industrial Internet of Things(IIoT):Opportunities,Challenges and Requirements in Manufacturing Businesses in Emergingeconomies[J].Procedia Computer Science,2023,217:856-865.
[2]GOYAL S,RAJAWAT A,SOLANKI R,et al.Integrating AI with cyber security for smart industry 4.0 application[C]//2023 International Conference on Inventive Computation Technologies(ICICT).IEEE,2023:1223-1232.
[3]ALOTAIBI L,SEHER S,MOHAMMAD N.Cyberattacks using chatgpt:Exploring malicious content generation through prompt engineering[C]//2024 ASU International Conference in Emerging Technologies for Sustainability and Intelligent Systems(ICETSIS).IEEE,2024:1304-1311.
[4]LI Y,LIU Q.A comprehensive review study of cyber-attacks and cyber security;Emerging trends and recent developments[J].Energy Reports,2021,7:8176-8186.
[5]WU J.Research on cyber mimic defense[J].Journal of Cyber Security,2016,1(4):1-10.
[6]ZHOU D,CHEN H,CHENG G,et al.Design and implementation of adaptive mimic voting device oriented to persistent connection[J].Journal on Communications,2022,43(6):71-84.
[7]WU J.Cyberspace endogenous safety and security[J].Enginee-ring,2022,15:179-185.
[8]CHOI J,GOH K.Dynamics of consensus formation on multiplex networks:the majority-vote model[C]//Proceedings of APS March Meeting.Ridge,NY:American Physical Society,2018.
[9]GUO W.Research on Mimic Architecture and Key Technologies of Distributed Storage System[D].Zhengzhou:Information Engineering University.2019.
[10]LIN S,LIU Q,WANG X.Competitive arbitration model formimic defense system[J]. Computer Engineering,2018,44(4):193-198.
[11]WEI S,ZHANG H,SU Y,et al.Majority voting algorithm and performance analysis based on high level heterogeneity[J].Computer Engineering,2020,46(3):237-245,253.
[12]SHEN C,CHEN S,WU C.Adaptive mimic defensive controller framework based on reputation and dissimilarity[J].Journal on Communications,2018,39(S2):173-180.
[13]PU L,BO Y,YOU W,et al.Heterogeneous executors output decision method for mimic cloud service[J].Journal of Information Engineering University,2020,21(3):344-351.
[14]GAO Z,JIA G,ZHANG W et al.An outlier-based optimization method for anamorphic rulings[J].Computer Application Research,2021,38(7):2066-2071.
[15]YANG X,CHENG G,LIU W,et al.Research on mimetic adjudication method based on deep learning[J].Journal of Communication,2024,45(2):79-89.
[16]WU Z,ZHANG F,GUO W,et al.A mimic arbitration optimization method based on heterogeneous degree of executors[J].Computer Engineering,2020,46(5):12-18.
[17]LU Y,HUANG J,CHENG Z,et al.A MultiIndex Mimic Voting Algorithm Based on Improved AHP-FCE Model[J].Journal of Beijing University of Posts and Telecommunications,2021,44(2):8-13.
[18]LIU Q,LIN S,GU Z.Heterogeneous redundancies scheduling algorithm for mimic security defense[J].Journal on Communications,2018,39(7):188-198.
[19]JIA H,PAN Y,LIU W H,et al.Dynamic scheduling algorithm for actuators based on high-order heterogeneity[J].Journal on Communication,2022,43(3):233-245.
[20]MOUSTAFA N,SLAY J.UNSW-NB15:a comprehensive dataset for network intrusion detection systems(UNSW-NB15 network data set)[C]//Proceedings of the 2015 Military Communications and Information Systems Conference(MilCIS).Piscataway:IEEE Press,2015:1-6.
[21]SHARAFALDIN I,LASHKARI A,GHORBANI A A.Toward generating a new intrusion detection dataset and intrusion traffic characterization[C]//Proceedings of the 4th International Conference on Information Systems Security and Privacy.SCITEPRESS-Science and Technology Publications,2018:108-116.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!