计算机与现代化 ›› 2024, Vol. 0 ›› Issue (07): 93-99.doi: 10.3969/j.issn.1006-2475.2024.07.014

• 算法设计与分析 • 上一篇    下一篇

基于贝叶斯攻击图的RFID系统安全博弈分析模型








  


  1. (1.南京邮电大学计算机学院,江苏 南京 210023; 2.南京邮电大学网络安全和可信计算研究所,江苏 南京 210023)
  • 出版日期:2024-07-25 发布日期:2024-08-08
  • 基金资助:
    国家自然科学基金资助项目(62102194); 江苏省六大人才高峰高层次人才项目(RJFW-111)

Security Game Analysis Model of RFID System Based on Bayesian Attack Graph

  1. (1. School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China; 2. Institute of Network Security and Trusted Computing, Nanjing University of Posts and Telecommunications, Nanjing 210023, China)
  • Online:2024-07-25 Published:2024-08-08

摘要: 针对RFID系统缺乏综合有效的风险管理与安全评估的问题,为了实现对RFID系统安全风险的有效分析以及对目标RFID系统整体风险状况的评估,本文提出一种基于贝叶斯攻击图的RFID系统安全博弈分析方法。在贝叶斯攻击图模型的基础上结合博弈思想对RFID系统的风险状况进行分析,将攻击者入侵系统的过程抽象为攻防双方的博弈模型。首先依据目标系统的相关信息确定攻防策略,并且通过对攻击者和防御者策略收益的计算,构建相应的攻防博弈矩阵,然后得出其纳什均衡状态,确定各参与者的最优策略,最后计算双方的期望收益,确定目标RFID系统的安全状态:若是攻击者期望收益大于防御者期望收益,则系统处于风险状态,反之系统则处于安全状态。实验结果表明,本文提出的博弈模型可以良好地实现对目标RFID系统的安全状况分析。

关键词: RFID, 贝叶斯攻击图, 安全博弈分析

Abstract: In view of the lack of comprehensive and effective risk management and security assessment of RFID systems, in order to achieve effective analysis of the security risks of RFID systems and the assessment of the overall risk status of target RFID systems, this paper proposes a Bayesian attack graph-based RFID system security game analysis method. On the basis of Bayesian attack graph model, combined with game thought, the risk situation of RFID system is analyzed, and the process of the attacker invading the system is abstracted into the game model of the attack and defense. This paper firstly determines the offensive and defensive strategy based on the relevant information of the target system, and constructs the corresponding offensive and defensive game matrix by calculating the strategic income of the attacker and the defender, then obtains the Nash equilibrium state, determines the optimal strategy of each participant, and finally calculates the expected income of both parties to determine the security state of the target RFID system: If the expected return of the attacker is greater than the expected return of the defender, the system is in the risk state; otherwise, the system is in the security state. The experiment results show that the game model proposed in this paper can well realize the security analysis of target RFID system.

Key words:  , RFID, Bayesian attack graph, security game analysis

中图分类号: