Network security protection method and device based on persistent attack simulation
By simulating continuous attacks and using machine learning to adjust protection strategies, the problem of insufficient assessment of traditional network security testing methods under complex attacks is solved, timely response to unknown threats and dynamic adaptation of the system are achieved, and network security protection capabilities are improved.
Patent Information
- Application Number
- CN202510943922.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-09
- Publication Date
- 2025-09-12
AI Technical Summary
Traditional network security testing methods are unable to comprehensively evaluate the system's performance under long-term and complex attacks, lack continuous attack simulation, cannot adjust protection strategies in a timely manner, and are difficult to deal with unknown or new attack methods.
By simulating different types of persistent attacks, monitoring system defense capabilities in real time, using machine learning models to adjust protection strategies, generating attack reports and conducting feedback loops, we can dynamically adapt to network threats.
It improves the real-time defense capability of the network security system and the timeliness of policy adjustments, can effectively respond to multi-stage persistent threats, and improve the overall network security level.
Smart Images

Figure CN120639428A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a network security protection method and device based on continuous attack simulation. Background Art
[0002] With the deep integration of cloud computing, the Internet of Things, and artificial intelligence technologies, the complexity and frequency of cyberattacks are growing exponentially. Attack methods have evolved from single vulnerabilities to multi-stage persistent threats, and targets have expanded from personal devices to critical infrastructure (such as energy grids, scientific research institutions, and cloud platforms). Traditional network security testing methods typically involve one-time penetration tests or rule-based security checks. These methods often fail to fully assess a system's performance against prolonged and complex attacks. Furthermore, without a continuous monitoring mechanism, the system may be unable to adjust its protection strategies in a timely manner once new threat types emerge. Relying solely on historical data and known attack patterns for predictions makes it difficult to respond to unknown or new attack methods. Summary of the Invention
[0003] Based on this, the present invention provides a network security protection method and device based on continuous attack simulation. By simulating different types of continuous attacks, the system's defense capabilities are monitored in real time, and the protection strategy is automatically adjusted according to the simulation results, thereby improving the overall network security level.
[0004] In a first aspect, an embodiment of the present invention provides a network security protection method based on continuous attack simulation, comprising:
[0005] Step S1, generating several types of simulated attack traffic;
[0006] Step S2, sending the simulated attack traffic to the target network system;
[0007] Step S3, a plurality of monitoring points deployed in the target network system collect performance indicator data of the target network system in real time;
[0008] Step S4, sending the performance indicator data of the target network system to the trained machine learning model to obtain the effectiveness of the protection measures of the target network system;
[0009] Step S5, adjusting the protection strategy of the target network system according to the effectiveness of the protection measures of the target network system;
[0010] Step S6: resend the simulated attack traffic to the target network system with updated protection strategy, and execute step S3.
[0011] Furthermore, the simulated attack traffic includes DDoS attacks, SQL injection attacks and cross-site scripting attacks.
[0012] Furthermore, the performance indicator data of the target network includes CPU usage, memory occupancy, network bandwidth utilization and data packet loss rate.
[0013] Furthermore, the evaluation criteria for the effectiveness of the protection measures of the target network system include the defense success ratio of the target network system, the defense response time of the target network system, the defense CPU usage rate and the memory occupancy rate of the target network system.
[0014] Furthermore, monitoring points are deployed in the target network system at locations including network boundaries, in front of key servers within the data center, and at the entrances of each subnet.
[0015] Furthermore, the network security protection method based on continuous attack simulation also includes:
[0016] The sensitivity of the intrusion detection system in the target network system is adjusted according to the effectiveness of the protection measures of the target network system.
[0017] Furthermore, the network security protection method based on continuous attack simulation also includes:
[0018] An attack report is generated according to the effectiveness of the protection measures of the target network system, wherein the attack includes the attack traffic type, attack time, attack intensity and the effectiveness of the protection measures of the target network system.
[0019] In a second aspect, the present invention further provides a network security protection method and apparatus based on continuous attack simulation, comprising:
[0020] Attack traffic generation module, used to generate several types of simulated attack traffic;
[0021] A simulated attack module, configured to send the simulated attack traffic to a target network system;
[0022] An indicator data monitoring module, which is used to collect performance indicator data of the target network system in real time from a number of monitoring points deployed in the target network system;
[0023] a protection effectiveness evaluation module, configured to send the performance indicator data of the target network system to the trained machine learning model to obtain the effectiveness of the protection measures of the target network system;
[0024] A protection adjustment module, configured to adjust the protection strategy of the target network system according to the effectiveness of the protection measures of the target network system;
[0025] The continuous simulated attack module is used to resend the simulated attack traffic to the target network system with updated protection strategy and execute the simulated attack module.
[0026] In a third aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any one of the network security protection methods based on continuous attack simulation in the first aspect.
[0027] In a fourth aspect, the present invention further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it executes any one of the network security protection methods based on continuous attack simulation in the first aspect.
[0028] The beneficial effects of adopting the above technical solution are as follows: this embodiment simulates real network attack scenarios by generating and sending various types of attack traffic to meet different testing needs. In addition, multiple monitoring points are deployed in the target network system to collect system performance indicator data in real time. These monitoring points can be dynamically adjusted according to the actual network topology to ensure that key nodes are fully monitored. The monitoring data not only includes basic information such as CPU usage, memory usage, network bandwidth utilization and packet loss rate, but also includes deeper security event logs and abnormal behavior records. All data is transmitted to the intelligent analysis platform in real time through an efficient transmission protocol to ensure the timeliness and accuracy of data analysis. Deep learning algorithms are used to process and analyze the data collected by the real-time monitoring module. By continuously accumulating historical data, the platform can improve prediction accuracy and generate optimization suggestions. Provide an intuitive visual interface to display real-time data analysis results and trend prediction charts to help managers quickly understand the current network status. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for describing the embodiments or the prior art.
[0030] Figure 1 This is a schematic diagram of a network security protection method based on continuous attack simulation in one embodiment of the present application;
[0031] Figure 2 This is a schematic diagram of a network security protection device based on continuous attack simulation in one embodiment of the present application. DETAILED DESCRIPTION
[0032] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. In order to explain the present invention in more detail, the network security protection method and device based on continuous attack simulation provided by the present invention are specifically described below in combination with the drawings.
[0033] Unless otherwise defined, the technical or scientific terms used in this application should have the usual meanings understood by people with ordinary skills in the field to which the invention belongs. The words "first", "second" and similar terms used in the present invention do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, words such as "one", "an" or "the" do not indicate a quantity limitation, but rather indicate the presence of at least one. Words such as "include" or "comprise" mean that the elements or objects preceding the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Words such as "connect" or "connected" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the object being described changes, the relative positional relationship may also change accordingly.
[0034] With the development of information technology, the complexity and frequency of cyberattacks are increasing. Traditional network security testing methods, typically consisting of one-time penetration tests or rule-based security checks, often fail to comprehensively assess a system's security performance under continuous, multi-dimensional attacks. Existing technologies use external and internal risk analysis units to collect and analyze a system's external and internal risk data. This dual-assessment system comprehensively assesses the system's network security status. While this approach can effectively identify timely security threats, it lacks the support of continuous attack simulation and cannot provide real-time feedback on dynamic security environments.
[0035] Based on this, combined with the Figure 1 The schematic diagram of the network security protection method based on continuous attack simulation is shown. The present invention proposes a network security protection method based on continuous attack simulation. By simulating different types of continuous attacks, the multi-dimensional corresponding data of the defense system of the target network system is monitored in real time. Based on the dynamic attack and defense game model, the reinforcement learning algorithm is used to automate the protection strategy, forming a closed-loop feedback mechanism to ensure that the target network system can dynamically adapt to new threats.
[0036] The embodiments of the present application provide an application scenario for a network security protection method based on continuous attack simulation. This application scenario includes the terminal devices provided in the embodiments, including but not limited to smartphones and computer devices, wherein the computer device can be at least one of a desktop computer, portable computer, laptop computer, mainframe computer, tablet computer, and the like. The terminal device generates simulated attack traffic to evaluate the defense effectiveness of the target network system and adjusts and updates the target network system's protection strategy based on the defense effectiveness, thereby continuously and efficiently improving the security of the target network system. For the specific implementation process, please refer to the embodiments of the network security protection method based on continuous attack simulation.
[0037] Step S1: Generate several types of simulated attack traffic.
[0038] Specifically, step S1 can be implemented by a continuous attack simulation engine. The simulated attack traffic includes but is not limited to DDoS attacks, SQL injection attacks, and cross-site scripting attacks.
[0039] DDoS attack (Distributed Denial of Service) is a distributed denial of service attack, which means hackers use DDOS attackers to control multiple machines to attack simultaneously in order to "hinder normal users from using services", thus forming a DDOS attack.
[0040] SQL injection attacks are a common security threat in which attackers manipulate backend database servers by injecting malicious SQL code into application input fields. This attack can lead to data leakage, data corruption, or complete control of the database by the attacker.
[0041] Cross-site scripting attacks take advantage of vulnerabilities left during web page development and use clever methods to inject malicious instruction codes into web pages, causing users to load and execute web programs maliciously created by attackers.
[0042] In addition, the persistent attack simulation engine in the present embodiment may also be equipped with an attack pattern library for storing a variety of known attack patterns and their corresponding parameter settings, allowing for flexible selection and combination of different types of attacks. Furthermore, the attack pattern library regularly obtains the latest attack pattern information from external threat intelligence sources to ensure the diversity and timeliness of simulated attacks.
[0043] Step S2: sending the simulated attack traffic to the target network system.
[0044] Step S3: Several monitoring points deployed in the target network system collect performance index data of the target network system in real time.
[0045] Specifically, a number of monitoring points are deployed in the target network system, and the locations of the monitoring points are dynamically adjusted according to the actual topology of the network, thereby ensuring that the key nodes in the target network system are fully monitored. The deployment locations of the above-mentioned monitoring points include but are not limited to the network boundary, in front of the key servers inside the data center, and at the entrances of each subnet; wherein, the monitoring points at the network boundary are used to monitor the traffic entering and leaving the target network, the monitoring points in front of the key servers inside the data center are used to protect core data assets, and the monitoring points at the entrances of each subnet are used to isolate the traffic in different areas. In addition, the monitoring points in this embodiment are also provided with the function of automatically discovering new devices, so that the devices newly added to the target network system will be identified and included in the monitoring range.
[0046] Furthermore, the performance indicator data of the target network collected in real time by each monitoring point includes CPU usage, memory usage, network bandwidth utilization and packet loss rate.
[0047] CPU utilization is a core metric for measuring device processing load. It refers to the percentage of CPU time spent processing non-idle tasks compared to total operating time. CPU utilization reflects the processor resource consumption of network security devices (such as firewalls, intrusion detection systems, and routers).
[0048] Memory usage refers to the amount of physical memory (RAM) resources that defense components continuously occupy while performing security tasks. Memory usage monitoring is used to prevent high usage from causing system vulnerabilities or becoming a springboard for attacks.
[0049] Network bandwidth utilization is a core metric for measuring the efficiency of security protection mechanisms in consuming network transmission resources. It refers to the ratio of the effective data transmission bandwidth actually used by defenses in the target network system to the theoretical maximum bandwidth of the network link. By analyzing utilization components in real time, network bandwidth utilization can predict defense bottlenecks and dynamically adjust them.
[0050] The Packet Loss Rate (PLR) is a key metric for measuring network transmission reliability and the effectiveness of defense mechanisms. It refers to the percentage of packets that fail to reach their destination due to defense measures, network congestion, device failure, or attack interference, compared to the total number of packets sent. This metric directly reflects the ability of network defenses to ensure data transmission integrity and is an important indicator for evaluating whether protection strategies excessively interfere with normal communications.
[0051] Step S4: Send the performance indicator data of the target network system to the trained machine learning model to obtain the effectiveness of the protection measures of the target network system.
[0052] Specifically, the evaluation criteria for the effectiveness of the target network system's protective measures are based on multiple factors, including the target network system's defense success rate (indicating the percentage of attacks the target network system can successfully defend against), the target network system's defense response time (indicating the time interval between the target network system detecting an attack and taking corresponding measures), and the target network system's defense CPU utilization and memory usage. Furthermore, in this embodiment, the specific parameters for evaluating the effectiveness of the target network's protective measures may also include performance indicator data collected at monitoring points, such as CPU utilization, memory usage, network bandwidth utilization, and packet loss rate, thereby quantifying the effectiveness of the protective measures in actual deployment.
[0053] Step S5: adjusting the protection strategy of the target network system according to the effectiveness of the protection measures of the target network system.
[0054] Specifically, the above-mentioned protective measures for adjusting the target network system can be obtained by processing and analyzing the collected data through the machine learning algorithm adopted by the intelligent analysis platform. The protective strategy for adjusting the target network system includes automatically updating firewall rules or other security configurations to enhance the defense capabilities of the target network system.
[0055] For example, if the effectiveness analysis results of the target network system's protection measures show that a DDoS attack has caused the network bandwidth utilization to approach saturation, the target network system's protection strategy can be adjusted to increase bandwidth or configure more effective traffic filtering rules; if the effectiveness analysis of the target network system's protection measures finds that there is abnormally high traffic from a certain IP address segment within a specific time period, the target network system's protection strategy can be adjusted to temporarily block access to the IP address segment.
[0056] Adjustments to firewall rules or security configurations should be made based on the specific protection strategy of the target network system. For example, if the protection strategy adjustment indicates the need to strengthen defenses against SQL injection attacks, add or update the corresponding rules in the firewall to filter out requests containing typical SQL injection signature strings.
[0057] In addition, this embodiment can also adjust the sensitivity setting of the intrusion detection system to identify potential threats earlier. Specifically, the sensitivity of the intrusion detection system in the target network system is adjusted according to the effectiveness of the protection measures of the target network system.
[0058] Step S6: resend the simulated attack traffic to the target network system with updated protection strategy, and execute step S3.
[0059] This embodiment is equipped with a feedback loop mechanism that regularly conducts comprehensive security assessments of the entire system and generates comprehensive reports for management personnel's reference. The comprehensive reports include not only technical indicators but also risk assessments and improvement suggestions, helping managers formulate long-term security policy plans. Furthermore, this embodiment can also provide a multi-verification mechanism for the target network system for updating protection policies. Before applying new protection policies, they are tested in an isolated environment to avoid system failures caused by misoperation. At the same time, a log is recorded for each policy update, detailing the configuration differences before and after the update and the implementation effects, facilitating subsequent audits and backtracking.
[0060] This embodiment also includes generating an attack report based on the effectiveness of the target network system's protective measures. The attack report includes the attack traffic type, attack time, attack intensity, and the effectiveness of the target network system's protective measures. The attack report can be exported in multiple formats (e.g., PDF and CSV) for subsequent analysis and archiving.
[0061] Furthermore, this embodiment can also employ deep learning algorithms to train performance indicator data collected by monitoring points, improving prediction accuracy by continuously accumulating historical data. A visualization interface is also provided to display analysis results and trend forecast charts for real-time performance indicator data, allowing managers to intuitively understand network status.
[0062] Furthermore, this embodiment allows users to manually input specific attack scenarios to facilitate customized testing for special situations. A graphical scenario editor is also provided, allowing users to drag and drop different attack components to build complex attack chains and specify specific parameters for each component.
[0063] Furthermore, this embodiment may also include a user interface module that allows administrators to view real-time monitoring data, historical records, and automatically generated security recommendations. The user interface module also supports multi-language switching and provides a mobile application, allowing administrators to access system status anytime, anywhere.
[0064] This embodiment can also integrate third-party security tools or services, such as vulnerability scanners and intrusion detection systems, to enhance the comprehensiveness and accuracy of the overall security assessment. The integration solution enables two-way data synchronization through API interfaces, ensuring seamless collaboration between all security tools.
[0065] The embodiments of the present invention simulate real-world network attack scenarios by generating and sending multiple types of attack traffic. This engine not only supports traditional attack modes such as DDoS, SQL injection, and cross-site scripting attacks, but also dynamically updates its attack library based on the latest threat intelligence, ensuring the diversity and timeliness of simulated attacks. Furthermore, a flexible attack combination mechanism is designed, allowing users to customize attack links and configure them through a graphical interface to meet diverse testing requirements. To ensure the authenticity and effectiveness of the simulation, the engine also provides detailed attack reports, including attack type, time, intensity, and system response. These reports can be exported in multiple formats (such as PDF and CSV) for subsequent analysis and archiving.
[0066] In the embodiment of the present invention, multiple monitoring points are deployed in the target network system to collect the system's performance indicator data in real time. These monitoring points can be dynamically adjusted according to the actual network topology to ensure that key nodes are fully monitored. In addition, the monitoring points have the function of automatically discovering new devices, which can identify new devices added to the network in real time and automatically include them in the monitoring scope. The monitoring data not only includes basic information such as CPU usage, memory usage, network bandwidth utilization, and packet loss rate, but also includes deeper security event logs and abnormal behavior records. All data is transmitted to the intelligent analysis platform in real time through an efficient transmission protocol to ensure the timeliness and accuracy of data analysis.
[0067] Furthermore, in an embodiment of the present invention, a deep learning algorithm is used to process and analyze the data collected by the real-time monitoring module. By continuously accumulating historical data, the platform can improve prediction accuracy and generate optimization suggestions. An intuitive visual interface is provided to display real-time data analysis results and trend forecast charts to help managers quickly understand the current network status. In addition, the platform supports users to manually enter specific attack scenarios to facilitate customized testing for special situations. Through a graphical scenario editor, users can drag and drop different attack components to build complex attack links and specify the specific parameters of each component. This flexibility enables the intelligent analysis platform to not only respond to known attacks, but also effectively identify and defend against new threats.
[0068] It should be understood that although the Figure 1 The steps in the flowchart are shown in the order indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Figure 1At least part of the steps may include multiple sub-steps or sub-stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0069] The embodiments disclosed in the present invention describe in detail the network security protection method based on continuous attack simulation. The method disclosed in the present invention can be implemented using various devices. Therefore, the present invention also discloses a network security protection device based on continuous attack simulation. Figure 2 , specific embodiments are given below to explain in detail.
[0070] Attack traffic generation module 201, used to generate several types of simulated attack traffic;
[0071] A simulated attack module 202 is configured to send the simulated attack traffic to a target network system;
[0072] The indicator data monitoring module 203 is used to collect the performance indicator data of the target network system in real time from several monitoring points deployed in the target network system;
[0073] A protection effectiveness evaluation module 204 is configured to send the performance indicator data of the target network system to the trained machine learning model to obtain the effectiveness of the protection measures of the target network system;
[0074] A protection adjustment module 205 is configured to adjust the protection strategy of the target network system according to the effectiveness of the protection measures of the target network system;
[0075] The continuous simulated attack module 206 is used to resend the simulated attack traffic to the target network system with updated protection strategy to execute the simulated attack module.
[0076] For the network security protection device based on continuous attack simulation, please refer to the definition of the method above, which will not be repeated here. Each module in the above device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor of the terminal device in the form of hardware, or can be stored in the memory of the terminal device in the form of software so that the processor can call and execute the operations corresponding to each of the above modules.
[0077] In one embodiment, the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-mentioned network security protection method based on continuous attack simulation.
[0078] The computer-readable storage medium may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), a hard disk, or ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium has storage space for program code for executing any of the steps of the above-described method. This program code can be read from or written to one or more computer program products, and the program code may be compressed in a suitable form.
[0079] In one embodiment, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the above-mentioned network security protection method based on continuous attack simulation when executing the computer program.
[0080] The computer device includes a memory, a processor, and one or more computer programs, wherein the one or more computer programs can be stored in the memory and configured to be executed by one or more processors, and the one or more application programs are configured to execute the above-mentioned network security protection method based on continuous attack simulation.
[0081] A processor may include one or more processing cores. The processor utilizes various interfaces and circuits to connect the various components within the entire computer device. It executes instructions, programs, code sets, or instruction sets stored in memory, and accesses data stored in memory to perform various functions of the computer device and process data. Optionally, the processor may be implemented in the form of at least one of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem handles wireless communications. It is understood that the modem may not be integrated into the processor and may be implemented separately via a communications chip.
[0082] The memory may include random access memory (RAM) or read-only memory (ROM). The memory may be used to store instructions, programs, codes, code sets, or instruction sets. The memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc. The data storage area may also store data created by the terminal device during use, etc.
[0083] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A network security protection method based on continuous attack simulation, characterized in that: include: Step S1, generating several types of simulated attack traffic; Step S2, sending the simulated attack traffic to the target network system; Step S3, a plurality of monitoring points deployed in the target network system collect performance indicator data of the target network system in real time; Step S4, sending the performance indicator data of the target network system to the trained machine learning model to obtain the effectiveness of the protection measures of the target network system; Step S5, adjusting the protection strategy of the target network system according to the effectiveness of the protection measures of the target network system; Step S6: resend the simulated attack traffic to the target network system with updated protection strategy, and execute step S3.
2. The network security protection method based on continuous attack simulation according to claim 1, characterized in that: The simulated attack traffic includes DDoS attacks, SQL injection attacks and cross-site scripting attacks.
3. The network security protection method based on continuous attack simulation according to claim 1, characterized in that: The performance indicator data of the target network system includes CPU usage, memory occupancy, network bandwidth utilization and packet loss rate.
4. The network security protection method based on continuous attack simulation according to claim 1, characterized in that: The effectiveness of the protection measures of the target network system includes the defense success rate of the target network system, the defense response time of the target network system, the defense CPU usage rate and memory usage rate of the target network system.
5. The network security protection method based on continuous attack simulation according to claim 1, characterized in that: The monitoring points are deployed in the target network system at the network boundary, in front of key servers inside the data center, and at the entrances of each subnet.
6. The network security protection method based on continuous attack simulation according to claim 1, characterized in that: Also includes: The sensitivity of the intrusion detection system in the target network system is adjusted according to the effectiveness of the protection measures of the target network system.
7. The network security protection method based on continuous attack simulation according to claim 1, characterized in that: Also includes: An attack report is generated according to the effectiveness of the protection measures of the target network system, wherein the attack includes the attack traffic type, attack time, attack intensity and the effectiveness of the protection measures of the target network system.
8. A network security protection device based on continuous attack simulation, characterized in that: include: Attack traffic generation module, used to generate several types of simulated attack traffic; A simulated attack module, configured to send the simulated attack traffic to a target network system; An indicator data monitoring module, which is used to collect performance indicator data of the target network system in real time from a number of monitoring points deployed in the target network system; a protection effectiveness evaluation module, configured to send the performance indicator data of the target network system to the trained machine learning model to obtain the effectiveness of the protection measures of the target network system; A protection adjustment module, configured to adjust the protection strategy of the target network system according to the effectiveness of the protection measures of the target network system; The continuous simulated attack module is used to resend the simulated attack traffic to the target network system with updated protection strategy and execute the simulated attack module.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security protection method based on continuous attack simulation according to any one of claims 1 to 7 are implemented.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, it executes the network security protection method based on continuous attack simulation according to any one of claims 1 to 7.
Citation Information
Cited By
Adaptive network defense and topology reconstruction system based on attack feature learning
CN121396603A
Protocol flood attack function test method and device, equipment and storage medium
CN122293440A