面向样本外攻击行为的FSK评估方法
网络出版日期: 2026-04-01
基金资助
山东省重点研发计划(2025CXGC010901);国家自然科学基金(62272119, U2468204)
版权
FSK evaluation method for out-of-sample attack behavior assessment
Online published: 2026-04-01
Copyright
随着网络攻击手段的日益复杂,入侵及攻击模拟(Breach and Attack Simulation,BAS)已成为网络安全评估的重要手段。其中,路径规划器(Planner)作为核心模块,其决策算法直接决定了模拟过程的覆盖性与有效性。然而,现有的决策算法在应对行为结果不确定性和评估样本外攻击行为时仍存在不足,限制了其应用效果。为此,提出了一种基于结构化建模、动态邻域调整、时间衰减机制结合自适应K近邻(K-Nearest Neighbors,KNN)算法的综合攻击行为评估方法:特征相似度自适应K近邻(Feature Similarity adaptive KNN,FSK)算法。通过执行结果反馈对执行过程变化的适应能力进行增强,并利用多目标平衡决策实现对攻击行为的综合评估。实验结果表明,FSK在攻击面覆盖度和样本外攻击行为准确率方面具有优势,平均指标达到90%,比现有算法提高了20%,为BAS路径规划器的进一步改进提供了新的思路。
谢汝忱 , 王春露 . 面向样本外攻击行为的FSK评估方法[J]. 网络空间安全科学学报, 2025 , 3(5) : 38 -47 . DOI: 10.20172/j.issn.2097-3136.250504
With the increasing sophistication of cyber-attacks, Breach and Attack Simulation (BAS) has emerged as a pivotal approach for cybersecurity assessment. Within the BAS framework, the Planner serves as a core module, where decision algorithms directly dictate the coverage and effectiveness of the simulation. However, existing decision algorithms face significant limitations in handling the uncertainty of behavioral outcomes and assessing out-of-sample attack behaviors, thereby constraining their practical utility. To address these challenges, this paper proposes Feature Similarity adaptive KNN (FSK), a comprehensive attack behavior evaluation method. FSK integrates structured modeling, dynamic neighborhood adjustment, and temporal decay mechanisms with an adaptive K-Nearest Neighbors (KNN) algorithm. The method enhances adaptability to execution changes through execution result feedback, and achieves a comprehensive evaluation of attack behaviors utilizing multi-objective balanced decision-making. Experimental results demonstrate that FSK achieves superior performance in terms of attack surface coverage and prediction accuracy for out-of-sample behaviors. The average performance metrics reach 90%, representing a 20% improvement over existing baselines. These findings provide new insights for advancing the design of BAS planners.
表 1 攻击行为的主要特征及含义Table 1 Main characteristics and meanings of aggressive behaviors |
| 特征名 | 含义 |
| adversary_id | 所属的策略ID |
| ability_id | 所属的能力ID |
| executor_platform | 执行行为的操作系统 |
| executor_name | 执行行为的终端 |
| command | 攻击行为的原始命令 |
| planner | 使用的决策算法 |
| agent_privilege | agent的权限 |
| host_architecture | 执行行为的主机架构 |
| facts_need | 行为需要的变量 |
| unlock_facts | 执行成功可获得的变量 |
| time | 执行行为时的时间戳 |
| trust_status | agent状态是否可信 |
| status | 执行结果 |
表 2 参与相似度计算的特征及含义Table 2 Characteristics and meanings involved in similarity calculation |
| 特征名 | 含义 |
| adversary_id | 所属的策略ID |
| ability_id | 所属的能力ID |
| executor_platform | 执行行为的操作系统 |
| executor_name | 执行行为的终端 |
| command | 攻击行为的原始命令 |
| planner | 使用的决策算法 |
| agent_privilege | agent的权限 |
| host_architecture | 执行行为的主机架构 |
| facts_need | 行为需要的变量 |
| trust_status | agent状态是否可信 |
| unlock_facts | 行为成功可获得的变量 |
表 3 算法指标Table 3 Algorithm indicators |
| 算法 | 覆盖率 | 准确率 | 可决策率 | 平均指标 |
| Random | 0.980 | 0.140 | 1.00 | 0.70 |
| Batch | 0.890 | 0.080 | 1.00 | 0.66 |
| Bucket | 0.730 | 0.080 | 1.00 | 0.60 |
| Look_ahead | 0.980 | 0.090 | 1.00 | 0.69 |
| Guided | 0.140 | 0.840 | 1.00 | 0.66 |
| Bayes | 0.930 | 0.110 | 0.16 | 0.40 |
| FSK | 0.996 | 0.695 | 1.00 | 0.90 |
| 1 |
Lawrence D, Kouremetis M, Applebaum A, et al. Guided planner[EB/OL]. (2022-12-06)[2025-08-29]. https://medium.com/@mitrecaldera/guided-planner-d65aea65451.
|
| 2 |
Reinstadler B M. AI attack planning for emulated networks[D]. Cambridge: Massachusetts Institute of Technology, 2021.
|
| 3 |
Chen J, Zhang J, Liu Y, et al. Vulnerability correlation, multi-step attack and exploit chain in breach and attack simulation[C]//2023 IEEE 12th International Conference on Cloud Networking (CloudNet). Hoboken, USA: IEEE, 2023: 398-402.
|
| 4 |
Applebaum A, Miller D, Strom B, et al. Intelligent, automated red team emulation[C]//Proceedings of the 32nd Annual Conference on Computer Security Applications. Los Angeles, USA: ACM, 2016: 363-373.
|
| 5 |
Sarraute C, Richarte G, Lucángeli O J. An algorithm to find optimal attack paths in nondeterministic scenarios[C]//Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence. Chicago, USA: ACM, 2011: 71-80.
|
| 6 |
Gianvecchio S, Kouremetis M, Applebaum A. Look ahead planner[EB/OL]. (2022-11-03)[2025-08-29]. https://medium.com/@mitrecaldera/look-ahead-planner-6f52ee041378.
|
| 7 |
Li J, Zhang Q, Zhang D, et al. Research on optimal strategies of SAS cybersecurity based on MDP[C]//2019 IEEE Sustainable Power and Energy Conference (iSPEC). Beijing, China: IEEE, 2019: 2078-2083.
|
| 8 |
Ren Y, Duan Z, Guan J, et al. Optimal DoS attacks on remote state estimation with continuous action spaces[C]//2024 IEEE International Conference on Unmanned Systems (ICUS). Xi’an, China: IEEE, 2024: 1153-1158.
|
| 9 |
Hasegawa K, Hidano S, Fukushima K. AutoRed: Automating red team assessment via strategic thinking using reinforcement learning[C]//Proceedings of the 14th ACM Conference on Data and Application Security and Privacy. Porto, Portugal: ACM, 2024: 325-336.
|
| 10 |
Usubyan K, Kouremetis M, Jellen C. MITRE Caldera Naive Bayes planner[EB/OL]. (2023-10-04)[2025-08-29]. https://medium.com/@mitrecaldera/mitre-caldera-naive-bayes-planner-1a581c2140c3.
|
| 11 |
Hong H, Juan G, Ben W. An improved KNN algorithm based on adaptive cluster distance bounding for high dimensional indexing[C]//2012 3rd Global Congress on Intelligent Systems. Wuhan, China: IEEE, 2012: 213-217.
|
| 12 |
Aggarwal C C, Hinneburg A, Keim D A. On the surprising behavior of distance metrics in high dimensional space[C]//International Conference on Database Theory. London, UK: Springer, 2001: 420-434.
|
| 13 |
Kouiroukidis N, Evangelidis G. The effects of dimensionality curse in high dimensional KNN search[C]//2011 15th Panhellenic Conference on Informatics. Kastoria, Greece: IEEE, 2011: 41-45.
|
| 14 |
Song Y, Gu Y, Zhang R, et al. Brepartition: Optimized high-dimensional KNN search with Bregman distances[J]. IEEE Transactions on Knowledge and Data Engineering. IEEE, 2020, 34 (3): 1053- 1065.
|
| 15 |
Zhang R, Liu Y. Multi feature small sample object recognition method based on DTW algorithm[C]//2018 IEEE 3rd Advanced Information Technology, Electronic and Automation Control Conference (IAEAC). Chongqing, China: IEEE, 2018: 2118-2122.
|
| 16 |
Zheng Q. An improved collaborative filtering algorithm based on expert trust and time decay[C]//2018 11th International Symposium on Computational Intelligence and Design (ISCID). Hangzhou, China: IEEE, 2018: 12-15.
|
| 17 |
Fan X, Hu Y, Zhang R, et al. Modeling temporal effectiveness for context-aware web services recommendation[C]//2015 IEEE International Conference on Web Services. New York, USA: IEEE, 2015: 225-232.
|
| 18 |
Zhang H, Wang Z, Xia W, et al. Weighted adaptive KNN algorithm with historical information fusion for fingerprint positioning[J]. IEEE Wireless Communications Letters. IEEE, 2022, 11 (5): 1002- 1006.
|
| 19 |
Dixit M, Sharma R, Shaikh S, et al. Internet traffic detection using Naïve Bayes and k-nearest neighbors (KNN) algorithm[C]//2019 International Conference on Intelligent Computing and Control Systems (ICCS). Madurai, India: IEEE, 2019: 1153-1157.
|
| 20 |
Sharma A. Enhancing recommendation systems: A comparative and optimization study of KNN-based algorithms[C]//2024 3rd International Conference for Advancement in Technology (ICONAT). Goa, India: IEEE, 2024: 1-7.
|
| 21 |
Liang J, Liu Q, Nie N, et al. An improved algorithm based on KNN and random forest[C]//Proceedings of the 3rd International Conference on Computer Science and Application Engineering. Sanya, China: ACM, 2019: 1-6.
|
| 22 |
Ling Y L, Zhang X, Zhang Y. Improved KNN algorithm based on probability and adaptive K value[C]//Proceedings of the 2021 7th International Conference on Computing and Data Engineering. Sanya, China: ACM, 2021: 34-40.
|
| 23 |
Liu L, Bai J, Yan H. Fine-grained point cloud classification based on adaptive KNN algorithm[C]//Proceedings of the 2024 International Conference on Intelligent Perception and Pattern Recognition. Xiamen, China: SPIE, 2024: 121-127.
|
| 24 |
Wettschereck D, Dietterich T. Locally adaptive nearest neighbor algorithms[C]//Advances in Neural Information Processing Systems 6 (NIPS 1993). Denver, USA: Morgan Kaufmann, 1993: 184-191.
|
| 25 |
Shen T, Wang Y, Du T, et al. Clustering algorithm based on k-value adaptive neighborhood selection[C]//2021 International Conference on Computational Science and Computational Intelligence (CSCI). Las Vegas, USA: IEEE, 2021: 604-608.
|
| 26 |
Taneja S, Gupta C, Aggarwal S, et al. MFZ-KNN—A modified fuzzy based K nearest neighbor algorithm[C]//2015 International Conference on Cognitive Computing and Information Processing (CCIP). Noida, India: IEEE, 2015: 1-5.
|
| 27 |
Chu H, Liu T, Yuan Y. Improved KNN algorithm based on local K value fitting[C]//Proceedings of the 2024 3rd Asia Conference on Algorithms, Computing and Machine Learning. Shanghai, China: ACM, 2024: 414-418.
|
| 28 |
Cover T, Hart P. Nearest neighbor pattern classification[J]. IEEE Transactions on Information Theory. IEEE, 1967, 13 (1): 21- 27.
|
| 29 |
Jiang F, Zhang Z, Chen P, et al. Naive Bayes text categorization algorithm based on TF-IDF attribute weighting[C]//Proceedings of the 2018 2nd International Conference on Computer Science and Artificial Intelligence. Shenzhen, China: ACM, 2018: 521-525.
|
/
| 〈 |
|
〉 |