针对攻防图构建中存在的状态爆炸问题,提出一种基于状态约减的攻防图生成算法。该算法在分析攻击者和目标网络特点的基础上,对独立状态节点的权限进行对比;其在保留最高权限节点的前提下,实现对低权限节点的约减,并去除冗余攻击路径。仿真实验表明算法具有计算复杂度低、能有效降低状态爆炸以及控制攻防图规模等优点。
To solve the issue of state explosion in attack-defense graph generation,an algorithm ofattack-defense graph generation based on state reduction is proposed. This algorithm compares theauthority of nodes in independent state on the basis of analyzing the characteristics of attacker and thetarget network. It achieves reduction to low-privileged nodes and elimination of redundant attack pathunder the premise of reserving nodes of highest permission. Simulation results show that the algorithmhas advantages of low computational complexity,effectively reducing state explosion and controlling thescale of attack-defense graph.