《计算机应用》唯一官方网站 ›› 2026, Vol. 46 ›› Issue (3): 847-856.DOI: 10.11772/j.issn.1001-9081.2025091182

• 网络空间安全 • 上一篇    下一篇

基于多域策略图的跨域网络防御策略冲突检测方法

刘馨璐1(), 常德显1,2, 张靖坤1, 张大伟1   

  1. 1.信息工程大学 密码工程学院,郑州 450001
    2.河南省信息安全重点实验室,郑州 450004
  • 收稿日期:2025-10-11 修回日期:2025-12-08 接受日期:2025-12-10 发布日期:2025-12-24 出版日期:2026-03-10
  • 通讯作者: 刘馨璐
  • 作者简介:常德显(1977—),男,河南邓州人,副教授,博士,主要研究方向:网络信息防御
    张靖坤(2001—),男,河南驻马店人,硕士研究生,主要研究方向:加密流量分析
    张大伟(1996—),男,安徽滁州人,硕士研究生,主要研究方向:网络安全管理。
  • 基金资助:
    中国博士后科学基金资助项目(GZC20240321)

Cross-domain network defense strategy conflict detection method based on multi-domain policy graph

Xinlu LIU1(), Dexian CHANG1,2, Jingkun ZHANG1, Dawei ZHANG1   

  1. 1.Department of Cryptography Engineering,Information Engineering University,Zhengzhou Henan 450001,China
    2.Henan Province Key Laboratory of Information Security,Zhengzhou Henan 450004,China
  • Received:2025-10-11 Revised:2025-12-08 Accepted:2025-12-10 Online:2025-12-24 Published:2026-03-10
  • Contact: Xinlu LIU
  • About author:CHANG Dexian, born in 1977, Ph. D., associate professor. His research interests include network information defense.
    ZHANG Jingkun, born in 2001, M. S. candidate. His research interests include encrypted traffic analysis.
    ZHANG Dawei, born in 1996, M. S. candidate. His research interests include network security management.
  • Supported by:
    China Postdoctoral Science Foundation(GZC20240321)

摘要:

针对可编程网络跨域防御策略冲突检测中存在域间协同能力不足、资源标识异构和检测效率低等问题,提出一种基于多域策略图的跨域网络防御策略冲突检测方法。首先,基于通用JSON语言构建意图驱动的防御策略模型,并通过语义标签注入实现防御意图与防御策略的精准关联,解决单域策略模型的封闭性问题;其次,利用分层哈希映射(LHM)算法生成全局资源标识(GRI),解决多控制器域的资源标识冲突问题;最后,构建多域联合策略图(MD-JPG),并整合跨域策略间的拓扑、动作与资源依赖关系,设计基于图遍历的四维冲突跨域检测算法(CDC-4D)精准识别动作冲突、规则覆盖冲突、资源竞争冲突及策略类型冲突。实验结果表明,在多控制器网络防御场景中,所提方法的策略冲突检测时延、内存占用、检测F1分数都取得了较好的结果。

关键词: 可编程网络, 防御策略冲突检测, 全局策略图, 分层哈希映射算法, 资源标识

Abstract:

Aiming at the problems such as insufficient inter-domain collaboration ability, heterogeneous resource identifiers and low detection efficiency in conflict detection of cross-domain defense strategies in programmable networks, a cross-domain defense strategy conflict detection method based on multi-domain policy graph was proposed. Firstly, an intent-driven defense strategy model was constructed on the basis of the general JSON language, and the precise association between defense intentions and defense strategies was achieved through semantic label injection, so as to solve closed problem of the single-domain strategy model. Secondly, the Layered Hash Mapping (LHM) algorithm was utilized to generate Global Resource Identifier (GRI), thereby solving the problem of resource identifier conflicts in multi-controller domains. Finally, by constructing a Multi-Domain Joint Policy Graph (MD-JPG), as well as integrating the topological, action and resource dependencies among cross-domain strategies, a Cross-domain Conflict Detection algorithm based on graph traversal in four Dimensions, (CDC-4D) was designed to identify action conflicts, rule coverage conflicts, resource competition conflicts and strategy type conflicts accurately. Experimental results show that in the multi-controller network defense scenarios, the strategy conflict detection latency, memory usage, and detection F1-score of the proposed method have achieved good results.

Key words: programmable network, defense strategy conflict detection, global policy graph, Layered Hash Mapping (LHM) algorithm, resource identifier

中图分类号: