Method and system for testing QinQ network security, terminal and storage medium

By constructing a test environment that includes attack simulation, traffic monitoring, and security assessment modules, test data packets of various attack types are generated. Behavioral data is collected and processed in real time, and strategies are optimized. This solves the problem of the lack of security assessment in existing QinQ network testing methods and realizes multi-dimensional security detection and proactive defense of QinQ networks.

CN121283709APending Publication Date: 2026-01-06SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511391773.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-01-06

AI Technical Summary

Technical Problem

Existing QinQ network testing methods mainly focus on functional connectivity and forwarding performance verification, lacking a systematic assessment of potential security threats at the label level. This leads to non-standard or abnormal label combinations potentially bypassing access control policies, causing security risks such as unauthorized access and data leakage.

Method used

A test environment is built that includes attack simulation, traffic monitoring and security assessment modules. Test data packets of various attack types are generated, behavioral data is collected and processed in real time, and analysis is performed based on a preset security assessment index system. The label verification mechanism and access control policies are optimized to form a closed-loop optimization process.

Benefits of technology

It enables multi-dimensional security detection at the QinQ network tag processing level, quantitatively assesses network security status, enhances proactive defense capabilities against tag-related security threats, and significantly improves network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121283709A_ABST
    Figure CN121283709A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security detection, and particularly relates to a QinQ network security test method and system, a terminal and a storage medium, and the method comprises the steps: constructing a QinQ network security test environment comprising an attack simulation module, a traffic monitoring module and a security evaluation module; the method comprises the following steps: generating a test data packet containing multiple attack types through an attack simulation module, injecting the test data packet into a to-be-tested QinQ network, collecting processing behavior data of the QinQ network on the test data packet in real time through a flow monitoring module, analyzing the processing behavior data through a security evaluation module, and generating a security score and a vulnerability report of the QinQ network; s4, optimizing a label verification mechanism and an access control strategy of the QinQ network according to the vulnerability report, and repeatedly executing the steps S2 to S4 until the security score reaches a preset threshold value; and the security protection capability of the QinQ network on a label processing layer can be comprehensively detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security testing technology, specifically relating to a testing method, system, terminal, and storage medium for the network security of QinQ. Background Technology

[0002] With the continuous expansion of network scale, QinQ technology (802.1Q-in-802.1Q), as an important means of VLAN extension, is widely used in carrier and enterprise networks. It achieves isolation and transparent transmission of multi-user services by encapsulating a service provider label (S-TAG) outside the user VLAN tag (C-TAG). However, existing QinQ mechanisms have significant shortcomings in security. The tag encapsulation and decapsulation process lacks a strict verification mechanism, allowing non-standard or abnormal tag combinations to bypass access control policies, leading to security risks such as unauthorized access and data leakage. Current testing methods for QinQ networks mainly focus on functional connectivity and forwarding performance verification, lacking a systematic assessment of potential security threats at the tag level. Traditional testing methods fail to fully simulate abnormal scenarios such as non-standard S-TAG / C-TAG combinations, tag out-of-bounds access, and cross-domain access. Furthermore, the evaluation indicators are singular, relying solely on connectivity judgments, making it difficult to quantify the network's ability to identify and handle abnormal traffic. Summary of the Invention

[0003] To address the shortcomings of existing technologies where current testing methods for QinQ networks primarily focus on functional connectivity and forwarding performance verification, lacking a systematic assessment of potential security threats at the tag level, this invention provides a testing method, system, terminal, and storage medium for QinQ network security.

[0004] In a first aspect, the present invention provides a method for testing the network security of QinQ, comprising:

[0005] S1. Construct a QinQ network security testing environment that includes an attack simulation module, a traffic monitoring module, and a security assessment module;

[0006] S2. Generate test data packets containing various attack types through the attack simulation module. The test data packets contain non-standard S-TAG, C-TAG, or abnormal tag combinations.

[0007] S3. Inject the test data packet into the QinQ network to be tested, and collect the QinQ network's processing behavior data on the test data packet in real time through the traffic monitoring module. The processing behavior data includes tag verification results, data packet forwarding path, and access control policy execution records.

[0008] S4. Based on the preset security assessment index system, the security assessment module analyzes the processing behavior data to generate a security score and vulnerability report for the QinQ network.

[0009] S5. Based on the vulnerability report, optimize the tag verification mechanism and access control policy of the QinQ network, and repeat steps S2 to S4 until the security score reaches the preset threshold.

[0010] Further improvements to this technical solution include step S1, which includes:

[0011] S11. Deploy the attack simulation module at the access layer edge of the test network and configure it to have custom encapsulation capabilities for IEEE 802.1Q and QinQ dual-layer labels. It supports setting the field values, priorities, and encapsulation order of S-TAG and C-TAG to simulate the generation environment of attack traffic.

[0012] S12. Deploy traffic monitoring modules in switches, aggregation layer devices and service access points of the QinQ network. Introduce bidirectional traffic into the traffic detection probe through port mirroring or splitter. The traffic detection probe has a built-in timestamp unit to record the transmission path and processing log of test data packets in the QinQ network with nanosecond-level accuracy.

[0013] S13. Build a security assessment module as a central analysis unit, integrating data storage, indicator calculation engine and vulnerability analysis model, while preloading indicator assessment algorithms and establishing real-time communication links with each monitoring node.

[0014] S14. The attack simulation module, traffic monitoring module and security assessment module are interconnected through the management network to realize closed-loop communication of test task distribution, behavioral data feedback and assessment result feedback.

[0015] Further improvements to this technical solution include step S2, which includes:

[0016] S21. Configure a tag tampering test scenario to generate non-standard tag data packets that differ from the legitimate S-TAG or C-TAG values ​​by ±1 to ±5, in order to simulate the behavior of users bypassing static access control policies by adjusting VLAN tags.

[0017] S22. Perform an unauthorized access test simulation, collect the outer S-TAG information corresponding to the target isolated VLAN, and construct a cross-domain QinQ data packet carrying the S-TAG to test the QinQ network's ability to intercept unauthorized users accessing other VLANs.

[0018] S23. Perform a tag overflow test to generate an abnormal tag data packet with an S-TAG or C-TAG value of 4096, which exceeds the VLAN ID range specified by the IEEE 802.1Q protocol, i.e., 0 to 4095, to verify the QinQ network's boundary handling and secure discarding mechanism for illegal tags.

[0019] S24. Conduct protocol compatibility testing. Construct data packets with valid outer tags according to the standard QinQ encapsulation format, embed test content with SQL injection, cross-site scripting, or virus signatures in their payload, and evaluate whether there are any security detection blind spots in the protocol parsing process.

[0020] Further improvements to this technical solution include step S3, which includes:

[0021] S31. Deploy distributed injection nodes on several physical ports in the access layer, and inject data packets with different types of abnormal tags into the QinQ network under test according to a preset frequency and traffic ratio.

[0022] S32. Enable port mirroring on switches and aggregation layer devices through the traffic monitoring module to capture the complete forwarding process of injected data packets in real time;

[0023] S33. Analyze the processing logs and forwarding information database (FIB) records of the QinQ network, extract the label verification results, actual forwarding paths, and policy execution actions of each test data packet, and form a processing behavior dataset with timestamps.

[0024] S34. Track the propagation behavior of abnormal labeled data packets, count the broadcast range, hop count and number of logical subnets affected by them in the QinQ network, and evaluate the stability and isolation effectiveness of the QinQ network under the propagation of abnormal labeled data packets.

[0025] Further improvements to this technical solution include step S4, which includes:

[0026] S41. Extract the number of legally recognized labels and the number of non-standard labels blocked from the collected processing behavior dataset, and calculate the label verification validity score;

[0027] S42. Calculate the access control strength score by statistically analyzing the success rate of blocking cross-VLAN access requests and the rejection rate of unauthorized device access, and combining the policy execution records.

[0028] S43. Monitor the proportion of abnormal labeled data packets dropped within a 1-second time window, record the time from the appearance of attack traffic to its suppression, and calculate the abnormal traffic handling capability score.

[0029] S44. Based on the tag verification validity score, access control strength score, and abnormal traffic handling capability score, and by weighting and summing the scores according to the weight coefficients corresponding to each score, a comprehensive security score for the QinQ network is generated. Root cause analysis is performed on individual indicators below the threshold, and a vulnerability report containing the vulnerability type and scope of impact is output.

[0030] Further improvements to this technical solution include step S4, which further includes:

[0031] The formula for calculating the label verification validity score is as follows:

[0032] s υ =(R legal ×0.6+R forge (×0.4)×100;

[0033] Among them, s υ The label validation validity score is used to evaluate the QinQ network's ability to distinguish between standard and non-standard label combinations; R legal The valid label recognition rate is defined as the ratio of the number of valid data packets that pass verification to the total number of valid test data packets; R forge The non-standard label interception rate is defined as the ratio of the number of non-standard label data packets actively discarded by the QinQ network to the total number of non-standard label test data packets.

[0034] The formula for calculating the access control strength score is:

[0035] s a =(R cross-valn ×0.7+R unauth (×0.3)×100;

[0036] Among them, s a The access control strength score reflects the reliability of the QinQ network access control mechanism. cross-vlan The cross-VLAN access interception success rate is defined as the ratio of the number of cross-domain request packets successfully blocked by the firewall or ACL policy to the total number of cross-domain test requests; R unauth The unauthorized device access rejection rate is defined as the ratio of the number of terminal access attempts that were rejected without valid authentication to the total number of unauthorized access attempts.

[0037] The formula for calculating the abnormal traffic handling capability score is:

[0038] s t =(D discard ×0.6+T supp (×0.4)×100;

[0039] Among them, s tThe abnormal traffic handling capability is scored to measure the system's real-time response performance; D discard The real-time drop rate of anomalous tagged data packets is defined as the ratio of the number of anomalous tagged data packets dropped by QinQ network devices within one second to the total number of similar test packets received within that second; T supp Attack traffic suppression speed is defined as the reciprocal of the time required from the first detection of abnormal traffic until its transmission rate drops below the safe baseline, and is used to quantify response latency;

[0040] The formula for calculating the overall security score of the QinQ network is as follows:

[0041] S total =w υ ·s υ +w a ·s a +w t ·s t +w p ·s p +w l ·s l ;

[0042] Among them, S total A comprehensive security score for the QinQ network; s p The protocol compatibility security score is calculated based on the non-standard data packet recognition rate and the standard external label fault tolerance capability, with a weight w. p =0.15; s l The log audit integrity score is calculated based on the detail of the alert logs and the accuracy of vulnerability location, with a weight w. l =0.10; w υ The label validation validity score s υ The weight, w υ =0.30; w a Score for access control strength a The weight, w a =0.25; w t Score for abnormal traffic handling capability s t The weight, w t =0.20.

[0043] Further improvements to this technical solution include step S5, which includes:

[0044] S51. When the tag verification validity score in the vulnerability report is lower than the preset threshold, configure a dynamic tag verification mechanism to periodically update the associated hash key of S-TAG and C-TAG.

[0045] S52. Deploy a digital certificate-based identity authentication process at the access layer, requiring the terminal to complete two-way authentication before sending QinQ data packets, that is, only authorized devices can perform tag encapsulation and network access.

[0046] S53. Establish an S-TAG / C-TAG combination whitelist database, pre-register the tag pairs of legitimate users to the access control table of the switch, and reject all data packets with unregistered tag pairs from entering the aggregation layer and above network areas.

[0047] S54. When the access control strength score in the vulnerability report is lower than the preset threshold, deploy a security gateway that supports deep packet inspection at the aggregation layer to further analyze the payload content of data packets that have passed tag verification, block data streams carrying abnormal protocol characteristics or unauthorized access behavior, and record source tracing logs.

[0048] Secondly, the present invention provides a testing system for QinQ network security, comprising:

[0049] The environment building module is used to build a QinQ network security testing environment that includes an attack simulation module, a traffic monitoring module, and a security assessment module.

[0050] The packet generation module is used to generate test packets containing various abnormal scenario types through the attack simulation module. The test packets contain non-standard S-TAG, C-TAG or abnormal tag combinations.

[0051] The traffic injection and collection module is used to inject test data packets into the QinQ network under test, and to collect the QinQ network's processing behavior data on the test data packets in real time through the traffic monitoring module. The processing behavior data includes tag verification results, data packet forwarding paths, and access control policy execution records.

[0052] The security assessment and analysis module is used to quantitatively analyze the collected processing behavior data based on a preset security assessment index system, and generate a security score and vulnerability report for the QinQ network.

[0053] The strategy optimization and iteration control module is used to adjust the tag verification mechanism and access control policy of the QinQ network based on the vulnerability report, and to trigger the packet generation module to re-execute the test process until the security score reaches the preset threshold.

[0054] Thirdly, the present invention provides a terminal, comprising:

[0055] Processor, memory, among which,

[0056] This memory is used to store computer programs.

[0057] The processor is used to retrieve and run the computer program from memory, causing the terminal to perform the terminal method described above.

[0058] Fourthly, the present invention provides a computer storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described in the above aspects.

[0059] The beneficial effects of this invention are as follows: The testing method and system for QinQ network security provided by this invention address the problems of incomplete test scenario coverage, single evaluation indicators, and lack of closed-loop optimization mechanisms in existing technologies, demonstrating significant technological advancements and practical application value. By constructing a dedicated testing environment comprising three functional modules—attack simulation, traffic monitoring, and security assessment—it can systematically simulate various risk scenarios such as non-standard tag tampering, cross-domain access, tag overflow, and protocol compatibility anomalies, comprehensively testing the security protection capabilities of the QinQ network at the tag processing layer. This invention introduces a multi-dimensional and quantifiable security assessment indicator system, combining key indicators such as tag verification effectiveness, access control strength, and abnormal traffic handling capabilities, along with their weighted calculation methods, to achieve accurate scoring and vulnerability localization of network security status, overcoming the limitations of traditional testing that relies solely on connectivity judgments. Furthermore, by generating vulnerability reports and driving iterative optimization of tag verification mechanisms (such as dynamic keys, certificate authentication, and whitelists) and access control policies (such as deep packet inspection and source blocking), a closed-loop process of "testing—assessment—optimization—retesting" is formed, significantly improving the QinQ network's proactive defense capabilities against tag-related security threats. Attached Figure Description

[0060] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0061] Figure 1 This is a schematic flowchart illustrating a method according to an embodiment of the present invention.

[0062] Figure 2 This is a schematic block diagram of a system according to an embodiment of the present invention.

[0063] Figure 3 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present invention. Detailed Implementation

[0064] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the specific embodiments. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0065] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.

[0066] The QinQ network security testing method provided in this embodiment of the invention is executed by a computer device, and correspondingly, the QinQ network security testing system runs on the computer device.

[0067] Figure 1 This is a schematic flowchart illustrating a method according to an embodiment of the present invention. Wherein, Figure 1 The implementing entity can be a QinQ network security testing system. Depending on different needs, the order of the steps in this flowchart can be changed, and some can be omitted.

[0068] like Figure 1 As shown, the method includes:

[0069] S1. Construct a QinQ network security testing environment that includes an attack simulation module, a traffic monitoring module, and a security assessment module;

[0070] S2. Generate test data packets containing various attack types through the attack simulation module. The test data packets contain non-standard S-TAG, C-TAG, or abnormal tag combinations.

[0071] S3. Inject the test data packet into the QinQ network to be tested, and collect the QinQ network's processing behavior data on the test data packet in real time through the traffic monitoring module. The processing behavior data includes tag verification results, data packet forwarding path, and access control policy execution records.

[0072] S4. Based on the preset security assessment index system, the security assessment module analyzes the processing behavior data to generate a security score and vulnerability report for the QinQ network.

[0073] S5. Based on the vulnerability report, optimize the tag verification mechanism and access control policy of the QinQ network, and repeat steps S2 to S4 until the security score reaches the preset threshold.

[0074] To facilitate understanding of the present invention, the following description further illustrates the QinQ network security testing method provided by the present invention, based on the principle of the QinQ network security testing method and the process of testing QinQ network security in the embodiments.

[0075] First, step S1 includes:

[0076] S11. Deploy the attack simulation module at the access layer edge of the test network and configure it to have custom encapsulation capabilities for IEEE 802.1Q and QinQ dual-layer labels. It supports setting the field values, priorities, and encapsulation order of S-TAG and C-TAG to simulate the generation environment of attack traffic.

[0077] S12. Deploy traffic monitoring modules in switches, aggregation layer devices and service access points of the QinQ network. Introduce bidirectional traffic into the traffic detection probe through port mirroring or splitter. The traffic detection probe has a built-in timestamp unit to record the transmission path and processing log of test data packets in the QinQ network with nanosecond-level accuracy. The transmission path and processing log include label changes, forwarding ports and ACL matching results.

[0078] S13. Build a security assessment module as a central analysis unit, integrating data storage, indicator calculation engine and vulnerability analysis model, while preloading indicator assessment algorithms and establishing real-time communication links with each monitoring node.

[0079] S14. The attack simulation module, traffic monitoring module and security assessment module are interconnected through the management network to realize closed-loop communication of test task distribution, behavioral data feedback and assessment result feedback.

[0080] Attack simulation module deployment and configuration:

[0081] Hardware selection and deployment location determination: A network traffic generator with a 10GE optical port (such as Spirent TestCenter C100) was selected as the hardware carrier for the attack simulation module. It was deployed in an independent rack at the edge of the test network access layer and directly connected to the backup service port of the access layer switch (such as Huawei S5735-L24P4X) through a dual-fiber bidirectional optical module to ensure that the module can directly inject test traffic into the QinQ network under test without affecting normal business data transmission.

[0082] Tag encapsulation capability configuration process: In the traffic generator's control software (such as Spirent TestCenterApplication v5.40), create a QinQ attack traffic test project and enter the tag configuration interface:

[0083] Enable the dual-layer label function, select the 802.1Q-in-802.1Q encapsulation type, configure the S-TAG field value range to 1-4095 and the C-TAG field value range to 1-4095, and support manual input of specific values ​​or batch generation through scripts;

[0084] Enter the priority configuration and set the 802.1p priority (level 0 to 7) for S-TAG and C-TAG. You can specify different priorities for the two tags to simulate attack traffic of different service levels.

[0085] In terms of encapsulation order, two optional orders are provided: C-TAG before S-TAG or S-TAG before C-TAG. The default order is C-TAG before S-TAG according to the QinQ standard. Custom encapsulation order is also supported to simulate non-standard protocol encapsulation attack scenarios.

[0086] After configuration, generate 10 test data packet samples using the traffic preview function to verify whether the tag encapsulation format, field values, and priorities meet the configuration requirements, ensuring that the module has custom encapsulation capabilities.

[0087] Attack traffic generation environment verification: 1000 test data packets carrying different S-TAG / C-TAG combinations (including legitimate and non-standard labels) were sent to the access layer switch. The traffic was captured through the port mirroring function of the switch. The data packet structure was analyzed using Wireshark (v4.2.2) to confirm that the attack simulation module can stably generate double-label data packets that meet the configuration requirements, and the data packet sending rate can be adjusted within the range of 1-1000pps, which meets the requirements for attack traffic simulation.

[0088] Traffic monitoring module deployment and configuration:

[0089] Monitoring Node Selection and Hardware Deployment: Deploy traffic monitoring probes (e.g., Sangfor NGAF-1000-B200) on the core switches (e.g., Huawei S9700), aggregation layer switches (e.g., Huawei S5735), and enterprise service access points (e.g., office area access switches) of the QinQ network. Configure port mirroring (SPAN) on the core switches and aggregation layer switches to mirror bidirectional traffic from all their service ports to the probe's monitoring port. Use optical splitters (e.g., Huawei OptiX OSN 1500) connected in series between the access switch and the terminal at the service access point to split bidirectional traffic to the probe's monitoring port, ensuring no traffic loss. Configure each traffic monitoring probe with an independent IP address (e.g., 192.168.100.1-192.168.100.10) and connect it to the management network for remote control and data backhaul.

[0090] Timestamp Unit Configuration: Access the traffic detection probe's management interface (WebUI), enable the NTP (Network Time Protocol) service, and synchronize the probe time with the NTP server in the network (accuracy ≤ 1ms) to ensure consistency across probes; enable the nanosecond-level timestamp function, setting it to record timestamps at both the ingress and egress times of data packets, with the timestamp format being "year-month-day hour:minute:second.nanosecond", and associate it with the source MAC (Media Access Control Address), destination MAC, and tag information of the data packets to form a complete timestamp record.

[0091] Transmission path and processing log collection configuration: Configure log collection rules in the probe, specifying the collection content including: S-TAG / C-TAG values ​​of data packets, tag change records (e.g., modification or stripping of tags by the switch), forwarding port number, and ACL (Access Control List) matching results (e.g., matched ACL rule number, allow / deny action).

[0092] Configure a log storage strategy using a "local storage + remote backup" mode. The probe stores the log data for the most recent 7 days locally (storage capacity ≥ 1TB), and backs up the log data to the log server (e.g., ELK Stack) in the management network every 5 minutes to avoid log loss.

[0093] Configure the log collection frequency to real-time collection to ensure that log recording is completed within 1ms after the data packet processing behavior occurs, meeting the nanosecond-level accuracy requirements.

[0094] Security assessment module setup and configuration:

[0095] Hardware and software architecture setup: An industrial control server (such as Dell PowerEdge R750) was selected as the hardware for the security assessment module, configured with an Intel Xeon Gold 6338 processor (28 cores), 128GB DDR4 memory, and a 2TB SSD hard drive to ensure powerful data processing and storage capabilities;

[0096] A Linux operating system (CentOS 8.5) is deployed on the server, along with data storage software (MySQL 8.0), an indicator calculation engine (Python 3.9 + Pandas library), and a vulnerability analysis model (a machine learning model built on TensorFlow 2.8), forming an integrated architecture for data storage, computational analysis, and vulnerability identification.

[0097] Evaluation algorithm preloading and configuration: The calculation formulas for indicators such as tag verification validity, access control strength, and abnormal traffic handling capability are written into Python algorithm scripts and imported into the indicator calculation engine; the baseline values ​​for each indicator are preset in the algorithm script (e.g., the baseline value for legal tag recognition rate is ≥95%, and the baseline value for non-standard tag interception rate is ≥90%), and the threshold judgment logic is configured. When the actual calculated value is lower than the baseline value, it is automatically marked as "indicator abnormal";

[0098] Train the vulnerability analysis model by importing historical vulnerability data (such as cases of label verification algorithm defects, ACL configuration errors, etc.) so that the model can automatically identify vulnerability types based on abnormal indicators and processing behavior data. The model training accuracy should reach more than 90%.

[0099] Real-time communication link establishment: Establishing a connection between the security assessment module and each traffic monitoring probe.

[0100] The TCP / IP (Transmission Control Protocol / Internet Protocol) communication link uses the MQTT (My Structured Query Language, an open-source relational database management system) protocol (a lightweight IoT communication protocol) to achieve real-time data transmission. The communication port is set to 1883, and the data transmission rate is ≥10Mbps. A link heartbeat detection mechanism is configured. The security assessment module sends a heartbeat packet to each probe every 10 seconds. If no response packet is received from the probe for 3 consecutive times, an alarm is automatically triggered and the link failure information is recorded to ensure the stability of the communication link.

[0101] Interconnection and closed-loop communication of the three major modules:

[0102] Management network setup: A separate management network is built using Gigabit Ethernet. The management ports of the attack simulation module (traffic generator), traffic monitoring module (each probe), and security assessment module (server) are interconnected through a switch (e.g., Huawei S5720). The management network IP segment is set to 192.168.200.0 / 24 to isolate it from the business network and prevent management data from affecting business traffic.

[0103] Test task distribution process: The security assessment module acts as the control center, creating test tasks in its management software (such as the self-developed QinQ security testing platform V1.0), specifying the test type (such as tag tampering test, unauthorized access test), data packet generation parameters (tag range, sending rate) and data collection requirements;

[0104] The test task instructions (in JSON format) are sent to the attack simulation module via the management network. After receiving the instructions, the attack simulation module parses and executes the corresponding data packet generation and injection operations, and at the same time returns a "task received successfully" confirmation message to the security assessment module.

[0105] Behavioral data feedback process: The traffic monitoring module collects and processes behavioral data in real time, and packages the data into JSON format data packets according to the strategy of "packaging 100 data packets at a time" and sends them back to the security assessment module through the management network. After receiving the data, the security assessment module first verifies the integrity of the data (such as checking whether fields are missing and whether timestamps are continuous). If the verification is successful, the data is stored in the MySQL database, and a "data received successfully" confirmation message is returned to the monitoring module. If the data is missing, the monitoring module is triggered to resend it.

[0106] Evaluation result feedback process: After the security evaluation module completes data analysis and scoring, it generates a security score report and a vulnerability report (PDF format), which are sent to the attack simulation module (for adjusting subsequent testing strategies) and the network management terminal (for testers to view) through the management network, respectively. After receiving the evaluation results, if the security score does not reach the preset threshold, the attack simulation module automatically adjusts the test data packet generation parameters according to the vulnerability report (such as increasing the proportion of non-standard label data packets for label verification vulnerabilities) to prepare for the next round of testing, forming a closed-loop communication.

[0107] Secondly, step S2 includes:

[0108] S21. Configure a tag tampering test scenario to generate non-standard tag data packets that differ from the legitimate S-TAG or C-TAG values ​​by ±1 to ±5, in order to simulate the behavior of users bypassing static access control policies by adjusting VLAN tags.

[0109] S22. Perform an unauthorized access test simulation, collect the outer S-TAG information corresponding to the target isolated VLAN, and construct a cross-domain QinQ data packet carrying the S-TAG to test the QinQ network's ability to intercept unauthorized users accessing other VLANs.

[0110] S23. Perform a tag overflow test to generate an abnormal tag data packet with an S-TAG or C-TAG value of 4096, which exceeds the VLAN ID range specified by the IEEE 802.1Q protocol, i.e., 0 to 4095, to verify the QinQ network's boundary handling and secure discarding mechanism for illegal tags.

[0111] S24. Conduct protocol compatibility testing. Construct data packets with valid outer tags according to the standard QinQ encapsulation format, embed test content with SQL injection, cross-site scripting, or virus signatures in their payload, and evaluate whether there are any security detection blind spots in the protocol parsing process.

[0112] Next, step S3 includes:

[0113] By generating non-standard labeled data packets with values ​​differing from the legitimate S-TAG / C-TAG by ±1 to ±5, typical attack behavior can be simulated where attackers use minor label adjustments to bypass static ACLs (Access Control Lists). Traditional tests often use completely random non-standard labels, making it difficult to reach vulnerabilities where adjacent labels in static policies are not blocked. This step, however, focuses on a difference range of ±1 to ±5, precisely covering the label adjustment strategies commonly used by attackers to evade detection (e.g., changing a legitimate S-TAG=100 to 101 to attempt privilege escalation). In actual testing, this scenario can accurately discover vulnerabilities in core switches where static ACLs only block legitimate labels and do not cover adjacent labels, avoiding the risk of unauthorized access due to policy oversights. Compared to traditional random label testing, this improves the vulnerability detection rate.

[0114] One of the core values ​​of QinQ networks is the isolation of different user VLANs through S-TAGs, while unauthorized access attacks directly undermine this isolation mechanism. This step, by collecting the outer S-TAG of the target isolated VLAN and constructing cross-domain QinQ packets, accurately simulates an attack scenario where an unauthorized user attempts to access other VLANs by constructing a non-standard (illegal) S-TAG. This directly verifies the network's ability to intercept unauthorized behaviors such as crossing C-TAGs with the same S-TAG or crossing domains with different S-TAGs. In operator multi-tenant QinQ network testing, this scenario revealed a vulnerability where the aggregation layer switch did not perform secondary verification on cross-domain S-TAG packets. This prevented the risk of tenant A accessing tenant B's financial VLAN by forging tenant B's S-TAG, effectively ensuring the isolation security of multi-tenant networks.

[0115] The IEEE 802.1Q protocol explicitly defines the VLAN ID range as 0-4095. Tag overflow (e.g., 4096) is a typical example of illegal protocol input. Some network devices, lacking boundary verification of tag values, may experience packet forwarding anomalies (e.g., broadcast storms) or device restarts. This step generates an abnormal packet with S-TAG / C-TAG = 4096, directly verifying the protocol compliance and boundary handling capabilities of QinQ network devices (switches, routers). In a campus network test, it was found that access layer switches did not discard packets with tag = 4096, but instead forwarded them to the core network, causing abnormal occupancy of the core switch's FIB (Forwarding Information Base) table. By fixing this vulnerability, the risk of attackers launching denial-of-service (DoS) attacks using tag overflow was avoided, ensuring the stable operation of network devices.

[0116] QinQ network devices typically validate tag validity, but they often overlook packets with valid tags but malicious payloads, creating a security blind spot at the protocol parsing layer. This step constructs packets with valid outer tags according to the standard QinQ encapsulation format, embedding SQL injection, cross-site scripting (XSS), or virus signatures only in the payload. This allows for precise testing of network devices (such as firewalls and intrusion detection systems) to determine if they prioritize tag validation over content detection.

[0117] S31. Deploy distributed injection nodes on several physical ports in the access layer, and inject data packets with different types of abnormal tags into the QinQ network under test according to a preset frequency and traffic ratio.

[0118] S32. Enable port mirroring on switches and aggregation layer devices through the traffic monitoring module to capture the complete forwarding process of injected data packets in real time;

[0119] S33. Analyze the processing logs and forwarding information database (FIB) records of the QinQ network, extract the label verification results, actual forwarding paths, and policy execution actions of each test data packet, and form a processing behavior dataset with timestamps.

[0120] S34. Track the propagation behavior of abnormal labeled data packets, count the broadcast range, hop count and number of logical subnets affected by them in the QinQ network, and evaluate the stability and isolation effectiveness of the QinQ network under the propagation of abnormal labeled data packets.

[0121] Then, step S4 includes:

[0122] S41. Extract the number of legally recognized labels and the number of non-standard labels blocked from the collected processing behavior dataset, and calculate the label verification validity score;

[0123] S42. Calculate the access control strength score by statistically analyzing the success rate of blocking cross-VLAN access requests and the rejection rate of unauthorized device access, and combining the policy execution records.

[0124] S43. Monitor the proportion of abnormal labeled data packets dropped within a 1-second time window, record the time from the appearance of attack traffic to its suppression, and calculate the abnormal traffic handling capability score.

[0125] S44. Based on the tag verification validity score, access control strength score, and abnormal traffic handling capability score, and by weighting and summing the scores according to the weight coefficients corresponding to each score, a comprehensive security score for the QinQ network is generated. Root cause analysis is performed on individual indicators below the threshold, and a vulnerability report containing the vulnerability type and scope of impact is output.

[0126] Furthermore, step S4 also includes:

[0127] The formula for calculating the label verification validity score is as follows:

[0128] s υ =(R legal ×0.6+R forge (×0.4)×100;

[0129] Among them, s υ The label validation validity score is used to evaluate the QinQ network's ability to distinguish between standard and non-standard label combinations; R legal The valid label recognition rate is defined as the ratio of the number of valid data packets that pass verification to the total number of valid test data packets; R forge The non-standard label interception rate is defined as the ratio of the number of non-standard label data packets actively discarded by the QinQ network to the total number of non-standard label test data packets.

[0130] The formula for calculating the access control strength score is:

[0131] s a =(R cross-vlan ×0.7+R unauth (×0.3)×100;

[0132] Among them, s a The access control strength score reflects the reliability of the QinQ network access control mechanism. cross-vlan The cross-VLAN access interception success rate is defined as the ratio of the number of cross-domain request packets successfully blocked by the firewall or ACL policy to the total number of cross-domain test requests; R unauth The unauthorized device access rejection rate is defined as the ratio of the number of terminal access attempts that were rejected without valid authentication to the total number of unauthorized access attempts.

[0133] The formula for calculating the abnormal traffic handling capability score is:

[0134] s t =(D discard ×0.6+T supp (×0.4)×100;

[0135] Among them, s t The abnormal traffic handling capability is scored to measure the system's real-time response performance; D discard The real-time drop rate of anomalous tagged data packets is defined as the ratio of the number of anomalous tagged data packets dropped by QinQ network devices within one second to the total number of similar test packets received within that second; T supp Attack traffic suppression speed is defined as the reciprocal of the time required from the first detection of abnormal traffic until its transmission rate drops below the safe baseline, and is used to quantify response latency;

[0136] The formula for calculating the overall security score of the QinQ network is as follows:

[0137] S total =w υ ·s υ +w a ·s a +w t ·s t +w p ·s p +w l ·s l ;

[0138] Among them, S total A comprehensive security score for the QinQ network; s p The protocol compatibility security score is calculated based on the non-standard data packet recognition rate and the standard external label fault tolerance capability, with a weight w. p =0.15; s l The log audit integrity score is calculated based on the detail of the alert logs and the accuracy of vulnerability location, with a weight w. l =0.10; w υ The label validation validity score s υ The weight, w υ =0.30; w a Score for access control strength a The weight, w a =0.25; w t Score for abnormal traffic handling capability s t The weight, w t =0.20.

[0139] The number of logs containing critical information refers to the total number of alarm logs generated by QinQ network devices (switches, traffic monitoring probes, security gateways, etc.) that fully record three categories of critical information: attack type, attack source address, and processing result. Specifically, the attack type must be clearly labeled as tag tampering, unauthorized access, tag overflow, protocol spoofing, etc.; the attack source address must include the source IP address, source MAC address, and access port number; and the processing result must clearly specify the actions taken, such as interception, discarding, alarming, or port blocking.

[0140] The total number of alarm logs refers to the total number of security alarm logs generated by all network devices for test packets during the test process. This includes alarm logs that only record some key information or have incomplete formats, but excludes non-security alarm logs such as those related to device operating status (e.g., port up / down).

[0141] The number of cases where vulnerabilities are accurately located through logs refers to the total number of cases where, based on information recorded in alarm logs, the network node (e.g., access layer switch A, aggregation layer firewall B) and specific functional module (e.g., tag verification module, ACL policy module) where the vulnerability exists are successfully located. The criteria for determining the location are: combining information such as the attack source address, processing device number, and error code in the logs, it can be clearly pointed to a defect in a specific functional module of a certain device, and the vulnerability is confirmed to exist through manual verification (e.g., logging into the device to check the configuration and testing the module's functionality).

[0142] The total number of vulnerability cases refers to the total number of all QinQ network security vulnerability cases identified during the testing process by analyzing and processing behavioral data through the security assessment module and combining it with the vulnerability analysis model. These include tag verification vulnerabilities, access control vulnerabilities, abnormal traffic handling vulnerabilities, protocol parsing vulnerabilities, etc. Each independent vulnerability point is counted as one case (for example, tag verification vulnerabilities and ACL vulnerabilities on the same device are counted as two cases respectively).

[0143] Alarm log detail level is the ratio of the number of logs containing key information to the total number of alarm logs; vulnerability location accuracy is the ratio of the number of cases where vulnerabilities are accurately located from the logs to the total number of logs; the log audit integrity score s is calculated by combining alarm log detail level and vulnerability location accuracy using a weighted summation method. l Among them, the accuracy of vulnerability location has a higher weight (60%), because vulnerability location is directly related to the efficiency of vulnerability remediation, while the detail of alarm logs is the basis of vulnerability location (weight 40%). The combination of the two can comprehensively reflect the completeness and practicality of log auditing.

[0144] In step S4, this invention introduces a multi-dimensional and quantifiable security assessment index system, significantly improving the accuracy of QinQ network security assessment. By calculating the tag verification validity score, it can objectively measure the network device's accuracy in recognizing legitimate tags and its ability to intercept non-standard tags, effectively identifying security blind spots caused by the lack of tag verification mechanisms. By calculating the access control strength score, it comprehensively evaluates the success rate of cross-VLAN access interception and the rate of unauthorized device access rejection, fully reflecting the execution reliability of ACL, firewall, and other policies in actual operation, and avoiding the risk of unauthorized access caused by logical configuration errors. By calculating the abnormal traffic handling capability score, it quantifies the system's drop efficiency and attack suppression response speed within a 1-second time window, truly reflecting the network's real-time handling performance of sudden abnormal traffic, and preventing broadcast storms or service interruptions caused by response delays.

[0145] Furthermore, a comprehensive security score for the QinQ network is generated through a weighted summation method, organically integrating various indicators to form a unified quantitative evaluation benchmark, overcoming the one-sidedness of traditional testing that relies solely on connectivity / disconnection judgments. The pre-set weighting mechanism (e.g., 30% for tag verification, 25% for access control) reflects the varying importance of different security dimensions, making the scoring results more scientific and comparable. Simultaneously, root cause analysis of individual indicators and the output of vulnerability reports achieve a leap from symptom detection to problem localization, providing a clear direction for subsequent optimization.

[0146] Finally, step S5 includes:

[0147] S51. When the tag verification validity score in the vulnerability report is lower than the preset threshold, configure a dynamic tag verification mechanism to periodically update the associated hash key of S-TAG and C-TAG.

[0148] S52. Deploy a digital certificate-based identity authentication process at the access layer, requiring the terminal to complete two-way authentication before sending QinQ data packets, that is, only authorized devices can perform tag encapsulation and network access.

[0149] S53. Establish an S-TAG / C-TAG combination whitelist database, pre-register the tag pairs of legitimate users to the access control table of the switch, and reject all data packets with unregistered tag pairs from entering the aggregation layer and above network areas.

[0150] S54. When the access control strength score in the vulnerability report is lower than the preset threshold, deploy a security gateway that supports deep packet inspection at the aggregation layer to further analyze the payload content of data packets that have passed tag verification, block data streams carrying abnormal protocol characteristics or unauthorized access behavior, and record source tracing logs.

[0151] In step S5, this invention proposes a closed-loop optimization mechanism based on vulnerability reports, which significantly improves the security defense capabilities and policy adaptability of the QinQ network. By implementing a dynamic tag verification mechanism (S51), the associated hash key of S-TAG and C-TAG is periodically updated, effectively preventing attackers from breaking through static tag verification through long-term observation or replay attacks, thus enhancing the timeliness and anti-cracking capability of tag authentication. By deploying a two-way identity authentication process based on digital certificates (S52), device-level identity binding is achieved at the access layer, ensuring that only terminals with certificates issued by a trusted CA can encapsulate QinQ tags and access the network, fundamentally eliminating unauthorized devices impersonating tags.

[0152] Furthermore, an S-TAG / C-TAG combined whitelist database (S53) is established, pre-registering the tag pairs of legitimate users in the switch access control table to form a fine-grained admission policy. This rejects all data packets with unregistered tag combinations from entering the core network area, strengthening the security isolation of the network boundary. When weak enforcement of the access control policy is detected, a security gateway supporting Deep Packet Inspection (DPI) is deployed at the aggregation layer (S54) to perform secondary analysis on the payloads of data packets that have passed tag verification. This identifies and blocks data flows carrying abnormal protocol characteristics or implicit unauthorized behavior, compensating for the limitations of relying solely on outer tag protection. Simultaneously, source tracing logs are recorded, providing a complete chain of evidence for security auditing and incident tracking.

[0153] In some embodiments, the QinQ network security testing system 200 may include multiple functional modules composed of computer program segments. The computer programs for each program segment in the QinQ network security testing system 200 may be stored in the memory of a computer device and executed by at least one processor to perform (see details). Figure 1 (Description) QinQ's network security testing function.

[0154] In this embodiment, the QinQ network security testing system 200 can be divided into multiple functional modules according to its functions, such as... Figure 2 As shown. The functional modules may include: an environment construction module 210, a data packet generation module 220, a traffic injection and acquisition module 230, a security assessment and analysis module 240, and a strategy optimization and iterative control module 250. The module referred to in this invention is a series of computer program segments that can be executed by at least one processor and perform a fixed function, stored in memory. In this embodiment, the functions of each module will be described in detail in subsequent embodiments.

[0155] Specifically, the environment construction module is used to build a QinQ network security testing environment that includes an attack simulation module, a traffic monitoring module, and a security assessment module; the packet generation module is used to generate test packets containing various abnormal scenario types through the attack simulation module. The test packets contain non-standard S-TAG, C-TAG, or abnormal tag combinations; the traffic injection and collection module is used to inject the test packets into the QinQ network under test and collect the QinQ network's processing behavior data of the test packets in real time through the traffic monitoring module. The processing behavior data includes tag verification results, packet forwarding paths, and access control policy execution records; the security assessment and analysis module is used to quantitatively analyze the collected processing behavior data based on a preset security assessment index system and generate a security score and vulnerability report for the QinQ network; the policy optimization and iteration control module is used to adjust the QinQ network's tag verification mechanism and access control policy according to the vulnerability report and trigger the packet generation module to re-execute the test process until the security score reaches a preset threshold.

[0156] Figure 3 This is a schematic diagram of the structure of a terminal 300 provided in an embodiment of the present invention. The terminal 300 can be used to execute the QinQ network security testing method provided in the embodiment of the present invention.

[0157] The terminal 300 may include a processor 310, a memory 320, and a communication module 330. These components communicate via one or more buses. Those skilled in the art will understand that the server structure shown in the figure does not constitute a limitation of the present invention. It may be a bus topology or a star topology, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0158] The memory 320 can be used to store the execution instructions of the processor 310. The memory 320 can be implemented by any type of volatile or non-volatile memory terminal or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. When the execution instructions in the memory 320 are executed by the processor 310, the terminal 300 is able to perform some or all of the steps in the above method embodiments.

[0159] The processor 310 serves as the control center of the storage terminal, connecting various parts of the electronic terminal via various interfaces and lines. It executes software programs and / or modules stored in the memory 320, and calls data stored in the memory to perform various functions of the electronic terminal and / or process data. The processor can be composed of integrated circuits (ICs), such as a single packaged IC or multiple packaged ICs with the same or different functions connected together. For example, the processor 310 may consist only of a central processing unit (CPU). In this embodiment of the invention, the CPU may have a single processing core or include multiple processing cores.

[0160] The communication module 330 is used to establish a communication channel, enabling the storage terminal to communicate with other terminals. It receives user data sent by other terminals or sends user data to other terminals.

[0161] The present invention also provides a computer storage medium, wherein the computer storage medium may store a program, which, when executed, may include some or all of the steps provided in the embodiments of the present invention. The storage medium may be a magnetic disk, an optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0162] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, or any other medium capable of storing program code. It includes several instructions to cause a computer terminal (which may be a personal computer, a server, or a second terminal, a network terminal, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0163] The same or similar parts between the various embodiments in this specification can be referred to mutually. In particular, the terminal embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.

[0164] In the embodiments provided by this invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between systems or modules may be electrical, mechanical, or other forms.

[0165] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0166] In addition, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.

[0167] Although the present invention has been described in detail with reference to the accompanying drawings and preferred embodiments, the present invention is not limited thereto. Various equivalent modifications or substitutions can be made to the embodiments of the present invention by those skilled in the art without departing from the spirit and essence of the invention, and such modifications or substitutions should all be within the scope of the present invention. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should also be covered within the protection scope of the present invention.

Claims

1. A method for testing QinQ network security, characterized in that, The method comprises the following steps: S1, constructing a QinQ network security test environment comprising an attack simulation module, a traffic monitoring module and a security evaluation module; S2, generating test data packets comprising multiple attack types by the attack simulation module, the test data packets comprising non-standard S-TAG, C-TAG or abnormal label combination; S3, injecting the test data packets into the QinQ network to be tested, collecting the processing behavior data of the test data packets by the traffic monitoring module in real time, the processing behavior data comprising label verification results, data packet forwarding path and access control policy execution record; S4, analyzing the processing behavior data based on a preset security evaluation index system by the security evaluation module to generate a security score and a vulnerability report of the QinQ network; S5, optimizing the label verification mechanism and the access control policy of the QinQ network according to the vulnerability report, and repeating steps S2 to S4 until the security score reaches a preset threshold.

2. The method of claim 1, wherein the method further comprises: Step S1 comprises: S11, deploying the attack simulation module at the edge of the access layer of the test network, configuring it with custom encapsulation capability of IEEE 802.1Q and QinQ double-layer labels, supporting setting of the field value, priority and encapsulation order of S-TAG and C-TAG to simulate the generation environment of attack traffic; S12, deploying the traffic monitoring module on the switches, aggregation layer devices and service access points of the QinQ network, introducing the bidirectional traffic into the traffic detection probe through port mirroring or optical splitter, the traffic detection probe being provided with a timestamp marking unit for recording the transmission path and processing log of the test data packet in the QinQ network at nanosecond level precision; S13, building the security evaluation module as a central analysis unit, integrating data storage, index calculation engine and vulnerability analysis model, preloading the evaluation algorithm of the index, and establishing real-time communication link with each monitoring node; S14, interconnecting the attack simulation module, the traffic monitoring module and the security evaluation module through the management network to realize closed-loop communication of test task issuing, behavior data returning and evaluation result feedback.

3. The method of testing QinQ network security according to claim 2, wherein, Step S2 comprises: S21, configuring a label tampering test scenario to generate non-standard label data packets with values differing from the legal S-TAG or C-TAG values by ±1 to ±5, for simulating the behavior of users bypassing static access control policies by adjusting VLAN labels; S22, performing unauthorized access test simulation, collecting the outer S-TAG information corresponding to the target isolated VLAN, and constructing cross-domain QinQ data packets carrying the S-TAG to test the interception ability of the QinQ network to unauthorized user access to other VLANs; S23, implementing label overflow test, generating abnormal label data packets with S-TAG or C-TAG values of 4096, which exceeds the VLAN ID range specified in IEEE 802.1Q protocol, i.e. 0 to 4095, to test the boundary processing and safe discarding mechanism of the QinQ network to illegal labels; S24, implement protocol compatibility test, construct outer label legal data packet in accordance with standard QinQ encapsulation format, embed test content with SQL injection, cross-site scripting or virus characteristic code in its payload, and evaluate whether there is a security detection blind area in the protocol analysis process.

4. The method of claim 2, wherein the method further comprises: Step S3 comprises: S31, deploy distributed injection nodes on a plurality of physical ports in the access layer, and inject data packets with different types of label anomalies into the QinQ network to be tested according to a preset frequency and flow proportion; S32, enable port mirroring function on the switch and aggregation layer device through the flow monitoring module to capture the complete forwarding process of the injected data packet in real time; S33, analyze the processing log and forwarding information base (FIB) record of the QinQ network, extract the label verification result, actual forwarding path and policy execution action of each test data packet, and form a timestamped processing behavior data set; S34, track the diffusion behavior of the abnormal label data packet, count the broadcast range, hop count and number of affected logical subnets triggered in the QinQ network, and evaluate the stability and isolation effectiveness of the QinQ network under the propagation of the abnormal label data packet.

5. The method of testing QinQ network security according to claim 4, wherein, Step S4 comprises: S41, extract the number of legal label identifications and the number of non-standard label interceptions from the collected processing behavior data set, and calculate the label verification effectiveness score; S42, count the interception success rate of cross-VLAN access requests and the rejection rate of unauthorized device access, and calculate the access control strength score in combination with the policy execution record; S43, monitor the discard proportion of abnormal label data packets within a 1-second time window, and record the time from the appearance of attack traffic to its suppression, and calculate the abnormal traffic processing capacity score; S44, based on the label verification effectiveness score, access control strength score and abnormal traffic processing capacity score, and according to the weight coefficients corresponding to each score, perform weighted summation to generate a comprehensive security score of the QinQ network, and perform root cause analysis on single indicators below the threshold value to output a vulnerability report containing vulnerability types and impact range.

6. The method of testing QinQ network security according to claim 5, wherein, Step S4 further comprises: The calculation formula of the label verification effectiveness score is: s v = (R legal × 0.6 + R forge × 0.4) x 100; wherein s v is the tag validation effectiveness score, used to evaluate the discriminative ability of the QinQ network for standard and non-standard tag combinations; R legal is the legal tag recognition rate, defined as the number of legal data packets that pass the validation correctly divided by the total number of legal test data packets; R forge is the non-standard tag blocking rate, defined as the number of non-standard tag data packets that are actively discarded by the QinQ network divided by the total number of non-standard tag test data packets. The calculation formula of the access control strength score is: s a = (R cross-vlan × 0.7 + R unauth × 0.3) x 100; wherein s a is an access control strength score, reflecting the execution reliability of the QinQ network access control mechanism; R cross-vlan is a cross-VLAN access interception success rate, defined as the ratio of the number of cross-domain request packets successfully blocked by the firewall or ACL policy to the total number of cross-domain test requests; R unauth is an unauthorized device access rejection rate, defined as the ratio of the number of terminal attempts to access without valid authentication to the total number of illegal access attempts; The calculation formula of the abnormal traffic processing capacity score is: s t = (D discard × 0.6 + T supp × 0.4) x 100; wherein s t is the abnormal traffic processing capability score, measuring the real-time response performance of the system; D discard is the real-time discard rate of abnormal tag packets, defined as the ratio of the number of abnormal tag packets discarded by the QinQ network device within 1 second to the total number of the same type of test packets received in that second; T supp is the attack traffic suppression speed, defined as the inverse of the time required for the transmission rate of abnormal traffic to drop below the safety baseline from the first detection of abnormal traffic, used to quantify the response delay; The calculation formula of the comprehensive security score of the QinQ network is: S total = w v · s v + w a · s a + w t · s t + w p · s p + w l · s l ; wherein S total is the security comprehensive score of QinQ network; s p is the protocol compatibility security score, which is calculated based on the non-standard packet identification rate and the standard external label fault tolerance ability, and the weight w p = 0.15; s l is the log audit integrity score, which is calculated based on the alarm log detail degree and the vulnerability positioning accuracy, and the weight w l = 0.10; w v is the weight of the label verification validity score s v , w v = 0.30; w a is the weight of the access control strength score s a , w a = 0.25; w t is the weight of the abnormal flow processing capacity score s t , w t = 0.

20.

7. The method of testing QinQ network security according to claim 5, wherein, Step S5 comprises: S51, when the label verification effectiveness score in the vulnerability report is below the preset threshold, configure a dynamic label verification mechanism by periodically updating the association hash key of S-TAG and C-TAG; S52, deploy a digital certificate-based identity authentication process on the access layer, and require the terminal to complete two-way identity authentication before sending QinQ data packets, i.e., only authorized devices can perform label encapsulation and network access; S53, establish an S-TAG / C-TAG combination whitelist database, pre-register the label pairs of legal users into the access control table of the switch, and reject all data packets with unregistered label combinations from entering the aggregation layer and above network areas; S54. When the access control strength score in the vulnerability report is lower than the preset threshold, deploy a security gateway that supports deep packet inspection at the aggregation layer to further analyze the payload content of data packets that have passed tag verification, block data streams carrying abnormal protocol characteristics or unauthorized access behavior, and record source tracing logs.

8. A system for testing QinQ network security, characterized in that, include: The environment building module is used to build a QinQ network security testing environment that includes an attack simulation module, a traffic monitoring module, and a security assessment module. The packet generation module is used to generate test packets containing various abnormal scenario types through the attack simulation module. The test packets contain non-standard S-TAG, C-TAG or abnormal tag combinations. The traffic injection and collection module is used to inject test data packets into the QinQ network under test, and to collect the QinQ network's processing behavior data on the test data packets in real time through the traffic monitoring module. The processing behavior data includes tag verification results, data packet forwarding paths, and access control policy execution records. The security assessment and analysis module is used to quantitatively analyze the collected processing behavior data based on a preset security assessment index system, and generate a security score and vulnerability report for the QinQ network. The strategy optimization and iteration control module is used to adjust the tag verification mechanism and access control policy of the QinQ network based on the vulnerability report, and to trigger the packet generation module to re-execute the test process until the security score reaches the preset threshold.

9. A terminal, characterized by comprising: include: processor; Memory used to store the processor's execution instructions; The processor is configured to perform the method according to any one of claims 1-7.

10. A computer readable storage medium storing a computer program, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-7.

Citation Information

Cited By

  • False data injection method, medium and equipment for AFDX (Avionics Full Duplex Switched Ethernet) network security test

    CN122120038A