A federal range cybersecurity talent teaching support system

By constructing a federal range cybersecurity talent training support system, the problems of resource silos and scenario distortion in existing cybersecurity teaching platforms have been solved. This system enables cross-institutional resource sharing and dynamic construction of high-fidelity training environments, thereby improving teaching effectiveness and talent training efficiency.

CN122288947APending Publication Date: 2026-06-26SICHUAN YILAN SITUATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SICHUAN YILAN SITUATION TECH CO LTD
Filing Date
2026-05-06
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing cybersecurity teaching platforms suffer from resource silos, distorted scenarios, and a disconnect between assessment and evaluation, making it difficult to achieve cross-regional and cross-industry teaching collaboration. They also lack a unified teaching resource sharing mechanism and a high-fidelity, realistic training environment.

Method used

Construct a federal range cybersecurity talent training support system, including a federal registration center for teaching resources, a federal range collaborative scheduling engine, an integrated teaching process execution module, a multi-source evaluation and fusion analysis module, and a privacy-protected data exchange gateway, to achieve cross-institutional resource sharing, dynamic training environment construction, full-process monitoring, and secure data transmission.

Benefits of technology

It enables cross-regional and cross-institutional sharing of teaching resources, dynamically constructs high-fidelity realistic training environments, supports full-process monitoring and evaluation, and cultivates practical cybersecurity talents who meet industry requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122288947A_ABST
    Figure CN122288947A_ABST
Patent Text Reader

Abstract

This invention discloses a federalized training support system for cybersecurity talent in a cybersecurity training range, belonging to the field of computer technology. It aims to solve the problems of isolated resources, fragmented teaching processes, and training content that is divorced from the needs of real-world industry applications in existing training ranges. The system includes a federalized registration center for training resources, a collaborative scheduling engine, an integrated teaching execution module, a multi-source evaluation and fusion analysis module, and a privacy-protected data exchange gateway. This application achieves trusted sharing of training resources, deep integration of industry and education, and accurate assessment of student capabilities, significantly improving the efficiency and practical skills of large-scale cybersecurity talent training.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer technology, specifically, it relates to a federal range cybersecurity talent training support system. Background Technology

[0002] Most current mainstream cybersecurity teaching platforms are built on single-machine simulations or local closed test ranges. Their core architecture is limited to the internal environment of a single institution, making it difficult to support cross-regional, cross-industry, and multi-level collaborative teaching. These platforms typically separate theoretical courses, experimental environments, and skills assessments, resulting in a fragmented teaching process and failing to form a closed-loop system from knowledge transfer to skills verification. Furthermore, due to the lack of unified standards and open interfaces, resources built by different institutions are isolated from each other, course content is outdated, and practical training scenarios are highly simplified, severely deviating from the real-world attack and defense environments of critical information infrastructure such as power, gas, and transportation, thus hindering the effective improvement of students' practical skills.

[0003] Among them, the federated range, as an emerging distributed security training paradigm, aims to construct a scalable and interconnected virtual attack and defense space by coordinating multiple independent nodes. Its basic goal is to achieve on-demand scheduling of teaching resources, dynamic generation of experimental environments, and unified execution of evaluation standards, while ensuring data ownership and system isolation. However, existing technologies have not yet effectively solved how to establish an efficient, secure, and auditable federated teaching collaboration mechanism under complex conditions involving multiple stakeholders and heterogeneous resources, especially in key areas such as curriculum design, range scheduling, virtual-real integration, and process monitoring, where significant gaps remain.

[0004] Existing technologies generally suffer from the following integration deficiencies: teaching resources are scattered across various universities or training institutions, lacking a unified aggregation and sharing mechanism; there is a lack of process integration and data linkage between theoretical teaching and practical training at testing ranges, making it difficult to achieve integrated "learning-practice-evaluation"; local training environments mostly rely on static virtual machines or container templates, unable to connect to real industry testing ranges as needed to recreate high-fidelity attack and defense scenarios; the teaching process lacks fine-grained behavior collection and dynamic analysis capabilities, making it difficult to quantify, optimize, and compare teaching effectiveness. These problems are particularly prominent in typical application scenarios such as multi-university joint training, industry-education integration training, and the construction of a cybersecurity talent pool. There is an urgent need for a cybersecurity talent teaching support system based on a federated architecture, supporting virtual-real integration, and possessing full-process monitoring capabilities to overcome the technical challenges of resource silos, scenario distortion, and disconnect between assessment and training. Summary of the Invention

[0005] The purpose of this invention is to provide a federal range cybersecurity talent training support system to solve the technical problems of resource silos, scenario distortion, and disconnect between assessment and evaluation.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0007] A federal range cybersecurity talent training support system includes:

[0008] The Teaching Resources Federal Registration Center module is used to receive and register teaching resource metadata information from multiple teaching institutions or industry units;

[0009] The Federation Range Cooperative Scheduling Engine module is used to match physical or virtual range instances that meet the conditions from the registered distributed range nodes based on the environmental requirement parameters in the teaching task request, and generate cross-domain resource scheduling instructions to dynamically build an isolated and reproducible training execution environment.

[0010] The integrated teaching process execution module is used to load the structured course package corresponding to the current teaching unit, trigger the theoretical learning unit, interactive experimental task unit and automated assessment unit in a preset sequence, and collect the students' operation logs, answer records and system behavior trajectory in real time at each stage;

[0011] The multi-source assessment and fusion analysis module is used to normalize, extract features, and model competency profiles of behavioral data generated by trainees in multiple dimensions, such as theoretical tests, experimental operations, and offensive and defensive confrontations, based on a predefined assessment index system, and generate standardized competency assessment reports.

[0012] The privacy-protected data exchange gateway module is used to perform data desensitization processing based on homomorphic encryption or differential privacy when transmitting teaching process data between different teaching institutions or industry test range nodes, and to control data access permissions through a zero-trust identity authentication mechanism to ensure that the original sensitive information does not leave the local domain.

[0013] Furthermore, in this invention, the functional configuration method of the teaching resource federation registration center module is as follows:

[0014] Externally input course documents, experiment scripts, and assessment question banks are converted into data structures that conform to the unified metadata specification. This structure includes a unique course code, the knowledge domain to which it belongs, prerequisite knowledge dependencies, target ability level, recommended learning path, experiment topology template, vulnerability type label, attack vector enumeration list, defense strategy set, scoring weight allocation table, and compliance declaration field.

[0015] A multi-dimensional inverted index is built for the standardized metadata entries, supporting fast retrieval by knowledge domain, capability level, industry scenario type, target range complexity, and required hardware resource specifications;

[0016] The system periodically polls the resource availability status of each registered node, including the online status of the test range instance, the remaining amount of computing resources, the remaining network bandwidth, and the security compliance status, and dynamically updates the status flags in the resource registry.

[0017] Furthermore, in this invention, the functional configuration method of the federated range collaborative scheduling engine module is as follows:

[0018] The target range configuration requirements declared in the teaching task request are analyzed. These requirements include operating system type and version, network topology, list of pre-built vulnerability components, traffic simulation intensity, log collection granularity, and isolation level.

[0019] Traverse the list of available target range nodes in the teaching resource federation registry center and filter out the set of candidate nodes that meet all hard constraints and whose resource load is below a preset threshold.

[0020] Call the remote deployment interface of the selected target range node, distribute the containerized experimental image or virtual machine template, configure network routing rules, firewall policies and monitoring agent programs, and finally generate a training environment instance with a unique session identifier.

[0021] The system monitors the runtime of the training environment. When the preset timeout threshold is reached or a signal indicating the end of the teaching process is received, the system automatically triggers an environment destruction operation to release the occupied computing and storage resources.

[0022] Furthermore, in this invention, the functional configuration method of the integrated teaching process execution module is as follows:

[0023] Pull the structured course package bound to the current teaching unit from the local cache or remote federated node. The course package consists of theoretical courseware files, interactive experimental guidance scripts, automatic scoring rule set and reference answer library.

[0024] According to the execution order defined in the course package, the theoretical learning interface, the experimental operation sandbox, and the evaluation and answer window are activated in sequence, and the preconditions for entering the next stage are checked at the end of each stage.

[0025] Records keyboard input sequences, mouse click coordinates, command line execution history, network connection attempt records, file system change logs, and process creation events at a fixed sampling frequency, and appends timestamps and user identification.

[0026] During the experimental operation phase, the trainees' behavior is judged in real time according to the preset checkpoint rules. If a key step is missed or an error is detected, context-related prompts will pop up.

[0027] Furthermore, in this invention, the functional configuration method of the multi-source evaluation fusion analysis module is as follows:

[0028] The theoretical test scores are linearly scaled on a percentage basis, the experimental operation completion rate is calculated based on the coverage of preset steps, and the offensive and defensive confrontation performance is weighted and synthesized by the number of successful defenses and the response delay, and mapped to a unified numerical range.

[0029] Based on the capability node definition in the cybersecurity knowledge graph, the normalized multidimensional data is projected onto the corresponding capability dimensions to form a quantitative score vector for trainees in sub-fields such as penetration testing, vulnerability analysis, incident response, and security hardening.

[0030] A sliding time window mechanism is used to continuously update the trainees' ability score vectors and combine them with historical trends to fit ability growth curves, identify ability weaknesses and potential for improvement.

[0031] In accordance with the standard format for cybersecurity talent development, output a comprehensive evaluation report that includes a capability radar chart, a knowledge point mastery heatmap, a summary of typical operation replays, and improvement suggestions.

[0032] Furthermore, in this invention, the function configuration method of the privacy-preserving data exchange gateway module is as follows:

[0033] Privacy-preserving transformations are performed on teaching process data that needs to be transmitted across domains. Additive noise injection is used for numerical indicators, entity replacement and generalization processing are used for operation log text, and aggregated statistical replacement is used for raw traffic data.

[0034] Before each data exchange, the requester's identity credentials, device fingerprint, and access context are verified. A temporary data access token is only granted if all verification items pass the preset security policy.

[0035] Establish an end-to-end encrypted communication link, use the national cryptographic algorithm SM4 to encrypt the transmitted payload, and use SM2 digital signature to ensure data integrity and non-repudiation;

[0036] Record the time, subject, object, operation type, and return result of each cross-domain data access in detail for use in subsequent security audits and compliance checks.

[0037] Furthermore, in this invention, in the multi-source evaluation and fusion analysis module, the experimental operation completion rate is calculated using the preset step coverage formula as follows:

[0038] in, Indicates completion level. The number of key steps actually performed by the trainees. The total number of critical steps defined for the task.

[0039] Furthermore, in this invention, in the multi-source evaluation and fusion analysis module, the offensive and defensive performance is weighted and synthesized by the number of successful defenses and the response delay, as shown in the formula:

[0040] in, The score indicates the level of confrontation. The percentage of successful defenses. For average response delay, For the maximum allowable delay, This is a weighting coefficient for the success rate of defense.

[0041] Compared with the prior art, the present invention has the following beneficial effects:

[0042] (1) This invention constructs a unified metadata standard and multi-dimensional index system through the teaching resource federation registration center module, and combines the dynamic resource matching and environment orchestration capabilities of the federation range collaborative scheduling engine module to break down geographical and institutional barriers. This solution supports cross-domain retrieval and scheduling of distributed range resources, realizes the efficient reuse of resources such as theoretical courses, experimental scripts, and industry scenarios, significantly improves the utilization rate of teaching resources, and provides technical support for cross-school joint training and industry-education integration training.

[0043] (2) This invention creates a closed-loop system of "theoretical learning - interactive experiment - automated assessment" through an integrated teaching process execution module. Combined with the dynamic ability profile modeling of the multi-source assessment fusion analysis module, it realizes real-time monitoring of the teaching process and multi-dimensional ability quantification. This solution not only solves the problem of poor transformation between theory and practice, but also accurately identifies students' ability shortcomings and generates personalized improvement suggestions, effectively shortening the talent training cycle and improving the effect of practical skills training.

[0044] (3) This invention uses differential privacy and homomorphic encryption technologies to desensitize sensitive data through a privacy-protected data exchange gateway module, and combines zero-trust authentication with national cryptographic algorithms (SM2 / SM4) to achieve end-to-end secure transmission. This solution achieves secure sharing of cross-institutional data while ensuring that the original sensitive information does not leave the local domain. It not only meets the collaborative needs in the industry-education integration scenario, but also complies with network security compliance requirements and protects the data source ownership of all participating parties.

[0045] (4) This invention connects to industry-level real-world target range nodes through a federated target range collaborative scheduling engine module, dynamically constructing high-fidelity attack and defense scenarios (such as those in the power and finance sectors) that include pre-set vulnerabilities and traffic simulations. This solution enables trainees to train in an environment close to real-world practice, effectively narrowing the gap between teaching content and industry practice needs, and cultivating more practical cybersecurity talents that meet industry requirements. Attached Figure Description

[0046] Figure 1 This is a schematic diagram of the overall technical architecture of the system of the present invention;

[0047] Figure 2 This is a logical framework diagram of the teaching process of the system of the present invention. Detailed Implementation

[0048] The present invention will be further described below with reference to the accompanying drawings and embodiments. The embodiments of the present invention include, but are not limited to, the following embodiments.

[0049] like Figure 1 , 2 As shown, this invention discloses a federated range cybersecurity talent training support system, aiming to solve technical problems in existing cybersecurity teaching platforms such as scattered teaching resources, closed experimental environments, fragmented practical training experiences, inconsistent evaluation standards, and difficulty in monitoring the teaching process. This invention achieves cross-regional, cross-institutional, and cross-industry sharing and collaborative scheduling of teaching resources by constructing a distributed teaching range network based on a federated computing architecture; it uses a unified course metadata model to structurally encapsulate theoretical courses, experimental tasks, and evaluation standards, establishing a closed-loop teaching process from knowledge learning to practical verification and then to competency assessment; and it introduces industry-level real-world attack and defense scenario mirrors and standardized interface protocols, opening up data channels between university teaching ranges and enterprise-level range resource pools while ensuring data ownership and privacy security, achieving a high degree of alignment between teaching content and industry practical needs.

[0050] The system includes a teaching resource federated registration center module, a federated range collaborative scheduling engine module, an integrated teaching process execution module, a multi-source evaluation and fusion analysis module, and a privacy-preserving data exchange gateway module. The teaching resource federated registration center module is used to receive and register teaching resource metadata information from multiple educational institutions or industry units. The configuration method for this module is as follows:

[0051] Externally input course documents, lab scripts, and assessment question banks are converted into a unified metadata structure containing a unique course code, knowledge domain, prerequisite dependencies, target ability level, recommended learning path, lab topology template, vulnerability type tags, attack vector enumeration list, defense strategy set, scoring weight allocation table, and compliance declaration fields. This structure ensures semantic consistency across all teaching resources, facilitating subsequent cross-domain retrieval and scheduling. The resource metadata standardization submodule is responsible for performing this conversion operation, internally maintaining a mapping rule library to map raw teaching materials of different formats to standard fields. For example, chapter titles in course documents are parsed into knowledge graph nodes, virtual machine configuration instructions in lab scripts are extracted into target environment configuration parameters, and question difficulty tags in the assessment question bank are converted into target ability level identifiers.

[0052] After standardization, the resource index construction submodule builds a multi-dimensional inverted index for the metadata entries. This index uses knowledge domain, capability level, industry scenario type, target range complexity, and required hardware resource specifications as primary key dimensions, maintaining a list of pointers to metadata records under each dimension. When a user initiates a resource retrieval request, the system quickly searches the corresponding dimension's index tree based on the query conditions and returns a set of resources that meet all conditions. For example, when requesting "training resources for intermediate penetration testing capabilities in a financial industry scenario," the system simultaneously matches entries with the knowledge domain "penetration testing," the capability level "intermediate," and the industry scenario type "finance," and further filters instances whose target range complexity does not exceed a preset threshold.

[0053] The resource status monitoring submodule periodically polls the resource availability status of each registered node. The polling period is set to 30 seconds. Each poll sends a heartbeat packet to the registered node to obtain its current online status, CPU utilization, remaining memory, disk space, network bandwidth usage, and security compliance status. If a node fails to respond to the heartbeat packet three times consecutively, its status is marked as offline; if the resource load exceeds 80%, it is marked as high-load and will not participate in new task scheduling. All status information is updated in real time to the resource registry in the federated registry center to ensure that scheduling decisions are based on the latest availability data.

[0054] The federated range collaborative scheduling engine module is used to match physical or virtualized range instances that meet the conditions from the registered distributed range nodes based on the environment requirement parameters in the teaching task request, and generate cross-domain resource scheduling instructions to dynamically construct isolated and reproducible training execution environments. The configuration method for this module is as follows:

[0055] The environment requirements parsing submodule first parses the target environment configuration requirements declared in the teaching task request. These requirements are embedded in the teaching task description in structured data form, explicitly specifying the operating system type and version (e.g., CentOS 7.9), network topology (e.g., a star topology containing 3 hosts), a list of pre-built vulnerable components (e.g., Apache Struts 2017 vulnerability, EternalBlue vulnerability), traffic simulation intensity (e.g., 1,000 HTTP requests per second), log collection granularity (e.g., recording all system calls), and isolation level (e.g., complete network isolation). The parsing results are encapsulated into an environment requirements object for subsequent matching.

[0056] The cross-domain resource matching submodule iterates through the list of available target range nodes in the teaching resource federation registry, comparing each node against the hard constraints in the environment requirement object. The matching process employs a two-stage screening mechanism: the first stage excludes all nodes that are offline or under high load; the second stage verifies the remaining nodes one by one to ensure that their supported operating system versions, deployable vulnerable components, maximum simulated traffic intensity, and other capabilities cover the requirements. Finally, a set of candidate nodes that meet all conditions and whose resource load is below a preset threshold (e.g., 70%) is retained. If the candidate set is empty, a resource insufficiency error is returned; otherwise, the process proceeds to the next stage.

[0057] The dynamic environment orchestration submodule selects the optimal node from the candidate set, prioritizing nodes with the closest geographical location, highest historical scheduling success rate, and largest resource reserves. Once selected, it calls the remote deployment interface exposed by that node to distribute a containerized experimental image or virtual machine template. The image or template pre-installs the required operating system, vulnerable components, and monitoring agent. Simultaneously, the system configures network routing rules to build the specified topology, sets firewall policies to restrict unauthorized access, and starts a log collection agent to record system behavior at a specified granularity. All configuration operations are executed through atomic transactions to ensure the consistency of the environment build. After completion, the system generates a unique session identifier and binds it to the training environment instance for subsequent access control and lifecycle management.

[0058] The environment lifecycle management submodule continuously monitors the runtime of the training environment. A timer starts counting from the environment activation time, and automatically triggers environment destruction when a preset timeout threshold (e.g., 4 hours) is reached or a teaching process end signal is received. The destruction process includes terminating all running containers or virtual machines, deleting temporary network configurations, clearing log caches, and releasing occupied computing and storage resources. After destruction, a resource release event is reported to the federated registry center, and the node availability status is updated.

[0059] The integrated teaching process execution module loads the structured course package corresponding to the current teaching unit, triggers the theoretical learning unit, interactive experimental task unit, and automated assessment unit sequentially according to a preset time sequence, and collects students' operation logs, answer records, and system behavior trajectories in real time at each stage. The configuration method for this module is as follows:

[0060] The course package loading submodule first pulls the structured course package bound to the current teaching unit from the local cache or a remote federated node. The course package uses a compressed archive format and contains theoretical courseware files (such as HTML or PDF format), interactive experiment guidance scripts (such as JSON format task descriptions and checkpoint rules), an automatic scoring rule set (such as YAML format scoring logic), and a reference answer library (such as encrypted standard operation sequences). After loading, the course package is decompressed into a memory sandbox for use in subsequent stages.

[0061] The stage switching control submodule activates the theoretical learning interface, experimental operation sandbox, and assessment and answer window sequentially according to the execution order defined within the course package. Each stage activation requires verification of preconditions. For example, before entering the experimental operation stage, the system verifies whether the student has completed all required readings from the theoretical learning stage; before entering the assessment stage, it verifies whether the experimental tasks have reached the minimum completion threshold. If the conditions are not met, the process is blocked, and the student is prompted to return to the previous stage.

[0062] The behavioral data collection submodule records multi-dimensional behavioral data during student operations at a fixed sampling frequency (e.g., 10 times per second). This includes keyboard input sequences (recording key codes and timestamps), mouse click coordinates (recording screen coordinates and click type), command line execution history (recording complete command strings and execution results), network connection attempt logs (recording target address, port, and protocol type), file system change logs (recording creation, modification, and deletion operations and file paths), and process creation events (recording process name, parent process ID, and startup parameters). All data is appended with precise timestamps (microsecond level) and user identification (e.g., student ID hash value), forming a structured behavioral log stream.

[0063] The real-time feedback generation submodule instantly judges trainee behavior based on preset checkpoint rules during the experimental operation phase. Checkpoint rules are stored in the form of a decision tree, with each node defining a behavior pattern matching condition. For example, "If the nmap scan command is not executed within ten minutes, a prompt will be triggered." When a trainee's behavior log stream matches the failure condition of a checkpoint, the system displays context-sensitive prompts, the content of which is provided by the guidance script in the course package. The prompts only display necessary clues, avoiding direct answers to maintain the challenge of the training.

[0064] The multi-source assessment and fusion analysis module is used to normalize, extract features, and model competency profiles of behavioral data generated by trainees across multiple dimensions, including theoretical tests, experimental operations, and offensive / defensive simulations, based on a predefined assessment index system, and generate standardized competency assessment reports. The configuration method for this module is as follows:

[0065] The specific steps for generating a standardized competency assessment report include: The data normalization submodule maps raw data from different assessment dimensions to a unified numerical range of 0-100. Theoretical test scores are linearly scaled on a percentage basis; experimental operation completion is calculated based on the coverage rate of preset steps, using the following formula:

[0066]

[0067] in, Indicates completion level. The number of key steps actually performed by the trainees. The total number of critical steps defined for the task. Offensive and defensive performance is weighted by the number of successful defenses and response latency, using the following formula:

[0068]

[0069] in, The score indicates the level of confrontation. The percentage of successful defenses. For average response delay, For the maximum allowable delay, The weighting coefficient for the defense success rate is set to 0.7.

[0070] The capability feature extraction submodule projects normalized multidimensional data onto corresponding capability dimensions based on capability node definitions in the cybersecurity knowledge graph. The knowledge graph predefines core capability domains such as penetration testing, vulnerability analysis, incident response, and security hardening, with each domain further subdivided into several sub-capability nodes. For example, logs of SQL injection command execution are mapped to the "Web Application Penetration" sub-node, and firewall rule configuration is mapped to the "Network Boundary Protection" sub-node. The projection process combines rule matching and pattern recognition to ensure that behavioral data is accurately assigned to the capability dimension.

[0071] The dynamic profile modeling submodule employs a sliding time window mechanism with a window length set at 30 days, continuously updating the trainee's ability score vector. After each new assessment, the system adds the latest score vector to the time window and removes historical records outside the window. Based on all score vectors within the window, the system fits a quadratic polynomial curve as the ability growth trajectory, calculating the slope of each ability dimension to identify improvement trends or stagnation risks. For dimensions with scores below a threshold (e.g., 60) in three consecutive assessments, the system marks them as ability weaknesses.

[0072] The standardized report generation submodule outputs a comprehensive evaluation report according to the standard format for cybersecurity talent development. The report includes a capability radar chart (showing scores for each core capability domain), a knowledge point mastery heatmap (using color intensity to indicate the degree of mastery of knowledge points), a summary of typical operation replays (extracting key operation segments with a timeline), and improvement suggestion text (automatically generating targeted training suggestions based on capability gaps). The report is generated in PDF format and digitally signed to ensure its integrity.

[0073] The privacy-preserving data exchange gateway module is used to perform data anonymization processing based on homomorphic encryption or differential privacy when transmitting teaching process data between different educational institutions or industry test range nodes. It also controls data access permissions through a zero-trust authentication mechanism to ensure that original sensitive information does not leave the local domain. The configuration method for this module is as follows:

[0074] The data anonymization submodule performs privacy-preserving transformations on teaching process data that needs to be transmitted across domains. For numerical indicators (such as scores and response times), additive noise injection is used, with the noise following a Gaussian distribution with a mean of zero and a standard deviation of 5 percent of the original value. For operation log text, entity replacement and generalization processing are used, replacing IP addresses with placeholders, usernames with generic identifiers, and obfuscating command parameters. For raw traffic data, aggregation statistics are used, transmitting only summary indicators such as the number of connections per minute and the number of bytes per minute, without transmitting the original packets.

[0075] The Zero Trust Authentication submodule performs multi-factor authentication before each data exchange. Authentication includes the requester's identity credentials (based on X.509 certificates), device fingerprint (based on hardware hashes and operating system characteristics), and access context (including time, location, and request purpose). All authentication items must pass a preset security policy defined in an access control list. Only when all authentications pass will the system grant a temporary data access token, which is valid for five minutes and requires re-authentication after expiration.

[0076] The encrypted transmission channel submodule establishes an end-to-end encrypted communication link. The transmitted payload is encrypted using the SM4 national cryptographic algorithm, and the key is dynamically generated through the SM2 key negotiation protocol. Simultaneously, SM2 digital signatures are used to sign the message digest, ensuring data integrity and non-repudiation. All encryption operations are performed in a dedicated security module, and the key never appears in plaintext form in memory.

[0077] The audit log recording submodule fully records every cross-domain data access event. Log fields include access time (accurate to milliseconds), subject identifier (requesting organization code), object identifier (accessed data resource ID), operation type (read, write, delete), return result (success, failure, rejection), and the token ID used. Logs are written to the distributed ledger in read-only mode to ensure immutability and are used for subsequent security audits and compliance checks.

[0078] The teaching resource federated registration center module runs on a highly available database cluster, employing a master-slave replication architecture to ensure data persistence. Resource metadata is stored in JSON document format, supporting full-text search and structured queries. The federated range collaborative scheduling engine module is deployed on a container orchestration platform, leveraging Kubernetes' scheduling capabilities to achieve cross-node resource allocation. The integrated teaching process execution module runs on a web application server, with a responsive front-end adaptable to various terminals, and a back-end maintaining real-time communication with student clients via WebSocket. The multi-source evaluation and fusion analysis module is deployed on a big data processing cluster, utilizing Spark for parallel computing to accelerate capability profile modeling. The privacy-preserving data exchange gateway module is deployed at the network boundary, integrating a hardware security module to accelerate the computation of national cryptographic algorithms.

[0079] Through the synergy of the above configuration methods and structures, the entire system achieves federated management of teaching resources, dynamic arrangement of training environments, integrated execution of teaching processes, multi-source fusion of competency assessments, and privacy protection of data exchange, effectively supporting the full-cycle training of cybersecurity talents from basic entry to expert training.

[0080] The above embodiments are merely one of the preferred embodiments of the present invention and should not be used to limit the scope of protection of the present invention. Any modifications or refinements made to the main design concept and spirit of the present invention that are not of substantial significance, but solve the same technical problem as the present invention, should be included within the scope of protection of the present invention.

Claims

1. A federal range cybersecurity talent training support system, characterized in that, include: The Teaching Resources Federal Registration Center module is used to receive and register teaching resource metadata information from multiple teaching institutions or industry units; The Federation Range Cooperative Scheduling Engine module is used to match physical or virtual range instances that meet the conditions from the registered distributed range nodes based on the environmental requirement parameters in the teaching task request, and generate cross-domain resource scheduling instructions to dynamically build an isolated and reproducible training execution environment. The integrated teaching process execution module is used to load the structured course package corresponding to the current teaching unit, trigger the theoretical learning unit, interactive experimental task unit and automated assessment unit in a preset sequence, and collect the students' operation logs, answer records and system behavior trajectory in real time at each stage; The multi-source assessment and fusion analysis module is used to normalize, extract features, and model competency profiles of behavioral data generated by trainees in multiple dimensions, such as theoretical tests, experimental operations, and offensive and defensive confrontations, based on a predefined assessment index system, and generate standardized competency assessment reports. The privacy-protected data exchange gateway module is used to perform data desensitization processing based on homomorphic encryption or differential privacy when transmitting teaching process data between different teaching institutions or industry test range nodes, and to control data access permissions through a zero-trust identity authentication mechanism to ensure that the original sensitive information does not leave the local domain.

2. The federal range cybersecurity talent training support system according to claim 1, characterized in that, The configuration method for the teaching resource federation registration center module is as follows: Externally input course documents, experiment scripts, and assessment question banks are converted into data structures that conform to the unified metadata specification. This structure includes a unique course code, the knowledge domain to which it belongs, prerequisite knowledge dependencies, target ability level, recommended learning path, experiment topology template, vulnerability type label, attack vector enumeration list, defense strategy set, scoring weight allocation table, and compliance declaration field. A multi-dimensional inverted index is built for the standardized metadata entries, supporting fast retrieval by knowledge domain, capability level, industry scenario type, target range complexity, and required hardware resource specifications; The system periodically polls the resource availability status of each registered node, including the online status of the test range instance, the remaining amount of computing resources, the remaining network bandwidth, and the security compliance status, and dynamically updates the status flags in the resource registry.

3. The federal range cybersecurity talent training support system according to claim 2, characterized in that, The configuration method for the federal range collaborative scheduling engine module is as follows: The target range configuration requirements declared in the teaching task request are analyzed. These requirements include operating system type and version, network topology, list of pre-built vulnerability components, traffic simulation intensity, log collection granularity, and isolation level. Traverse the list of available target range nodes in the teaching resource federation registry center and filter out the set of candidate nodes that meet all hard constraints and whose resource load is below a preset threshold. Call the remote deployment interface of the selected target range node, distribute the containerized experimental image or virtual machine template, configure network routing rules, firewall policies and monitoring agent programs, and finally generate a training environment instance with a unique session identifier. The system monitors the runtime of the training environment. When the preset timeout threshold is reached or a signal indicating the end of the teaching process is received, the system automatically triggers an environment destruction operation to release the occupied computing and storage resources.

4. The federal range cybersecurity talent training support system according to claim 3, characterized in that, The configuration method for the integrated teaching process execution module is as follows: Pull the structured course package bound to the current teaching unit from the local cache or remote federated node. The course package consists of theoretical courseware files, interactive experimental guidance scripts, automatic scoring rule set and reference answer library. According to the execution order defined in the course package, the theoretical learning interface, the experimental operation sandbox, and the evaluation and answer window are activated in sequence, and the preconditions for entering the next stage are checked at the end of each stage. Records keyboard input sequences, mouse click coordinates, command line execution history, network connection attempt records, file system change logs, and process creation events at a fixed sampling frequency, and appends timestamps and user identification. During the experimental operation phase, the trainees' behavior is judged in real time according to the preset checkpoint rules. If a key step is missed or an error is detected, context-related prompts will pop up.

5. The federal range cybersecurity talent training support system according to claim 4, characterized in that, The configuration method for the multi-source evaluation fusion analysis module is as follows: The theoretical test scores are linearly scaled on a percentage basis, the experimental operation completion rate is calculated based on the coverage of preset steps, and the offensive and defensive confrontation performance is weighted and synthesized by the number of successful defenses and the response delay, and mapped to a unified numerical range. Based on the capability node definition in the cybersecurity knowledge graph, the normalized multidimensional data is projected onto the corresponding capability dimensions to form a quantitative score vector for trainees in sub-fields such as penetration testing, vulnerability analysis, incident response, and security hardening. A sliding time window mechanism is used to continuously update the trainees' ability score vectors and combine them with historical trends to fit ability growth curves, identify ability weaknesses and potential for improvement. In accordance with the standard format for cybersecurity talent development, output a comprehensive evaluation report that includes a capability radar chart, a knowledge point mastery heatmap, a summary of typical operation replays, and improvement suggestions.

6. The federal range cybersecurity talent training support system according to claim 5, characterized in that, The configuration method for the privacy-protected data exchange gateway module is as follows: Privacy-preserving transformations are performed on teaching process data that needs to be transmitted across domains. Additive noise injection is used for numerical indicators, entity replacement and generalization processing are used for operation log text, and aggregated statistical replacement is used for raw traffic data. Before each data exchange, the requester's identity credentials, device fingerprint, and access context are verified. A temporary data access token is only granted if all verification items pass the preset security policy. Establish an end-to-end encrypted communication link, use the national cryptographic algorithm SM4 to encrypt the transmitted payload, and use SM2 digital signature to ensure data integrity and non-repudiation; Record the time, subject, object, operation type, and return result of each cross-domain data access in detail for use in subsequent security audits and compliance checks.

7. The federal range cybersecurity talent training support system according to claim 6, characterized in that, In the multi-source evaluation and fusion analysis module, the experimental operation completion rate is calculated using the preset step coverage formula as follows: in, Indicates completion level. The number of key steps actually performed by the trainees. The total number of critical steps defined for the task.

8. The federal range cybersecurity talent training support system according to claim 7, characterized in that, In the multi-source evaluation and fusion analysis module, the offensive and defensive performance is weighted and synthesized using the following formula based on the number of successful defenses and response latency: in, The score indicates the level of confrontation. The percentage of successful defenses. For average response delay, For the maximum allowable delay, This is a weighting coefficient for the success rate of defense.