基于人工智能的网络空间防御技术
2021-08-16赵宾华杨国瑞贾哲
赵宾华 杨国瑞 贾哲



摘要:网络空间是信息化战争独立的作战域,该领域的网络攻防行动快速但会产生海量的网络事件,对传统的点对点防御理念和堡垒式安全防御体提出了巨大挑战,人工智能和深度学习是未来网络空间防御的一个重要研究方向。在阐述传统网络防御模式和人工智能在网络防御的研究现状基础上,提出并设计了基于人工智能的网络安全防御系统,重点阐述了对网络协议攻击、入侵检测、网络异常行为的检测方案,分析了基于人工智能的网络防御系统的优势以及未来前景。
关键词:人工智能;网络防御;入侵检测;深度学习
中图分类号:TP393文献标志码:A文章编号:1008-1739(2021)12-57-4
Cyberspace Defense Technology Based on Artificial Intelligence
ZHAO Binhua,YANG Guorui,JIA Zhe
(The 54th Research Institute ofCETC,Shijiazhuang 050081,China)
Abstract: The military cyberspace is an independent combat domain for information warfare. The cyber attack and defense actions in this filed is fast and can produce a large number of network events,that presents great challenges to the traditional point-to-point defenses concept and fortress security defense systems. The technology of artificial intelligence and deep learning is an important research direction of cyber defense. On the basis of expounding the traditional cyber defense and the research status of artificial intelligence in cyber defense,the network defense system based on artificial intelligence is proposed and designed,and the network protocol attacks, intrusion detection,and network anomaly detection scheme are expounded in detail. At last,the advantages of network defense system based on artificial intelligence and the future prospects are analyzed.
Keywords:artificial intelligence;network defense; intrusion detection;deep learning
0引言
网络空间中的各种行为是物理作战域中各种作战实体行为的体现,且网络空间中的行为往往先于物理空间的行为,是作战实体的行为意图,网络空间行为感知是其他物理作战空间态势感知信息的重要来源,通过对网络空间行为进行准确感知、认知和理解,对准确把握敌方作战意图、作战行动具有很大帮助。信息化战争中,敌我双方会在网络空间,通过冒充合法用户、捕获操纵对方节点等在敌军信息系统实现病毒木马注入、伪造虚假以及篡改转发作战指令等攻击行为,需要在网络空间对异常行为进行感知、识别、定位和跟踪。
传统通信安全解决方案一般是通过捕获协议或异常流量、状态日志的特征来检测网络空间的异常行为,从而防御针对作战网络的安全威胁。……
