Network testing method and apparatus, electronic device, storage medium, and program product

By building a vulnerability knowledge graph and real-time patching of network nodes, the penetration test timeliness caused by changes in network nodes is solved, and a network security assessment that is closer to reality is achieved, and the timeliness and accuracy of penetration tests is improved.

WO2025148665A1PCT designated stage expired Publication Date: 2025-07-17STATE GRID INFORMATION & TELECOMM GRP CO LTD +2

Patent Information

Application Number
PCT/CN2024/141293
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-09
Filing Date
2024-12-23
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

In the prior art, the network penetration testing method based on reinforcement learning fails to effectively respond to network node service and topology changes, resulting in poor timeliness of penetration test results and ignores the impact of network node patches on penetration tests, resulting in the test results not being realistic enough.

Method used

By building a vulnerability knowledge graph, obtaining the target network node information in real time, determining the virtual network topology, and using patch information to patch exploited network nodes, performing virtual network penetration tests, and generating vulnerability and defensive reports.

Benefits of technology

Improve the timeliness of penetration testing, evaluate vulnerabilities and introduce patches and defense mechanisms, making the conclusions of intelligent confrontation closer to reality and providing real-time network security assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024141293_17072025_PF_FP_ABST
    Figure CN2024141293_17072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a network testing method and apparatus, an electronic device, a storage medium, and a program product. The method comprises: obtaining target network node information of a target network node, and determining a virtual network topology on the basis of the target network node information; by using a vulnerability knowledge graph, determining target patch information and target vulnerability information corresponding to the target network node; on the basis of preset network node rewards and attack operation success rates, performing a virtual network penetration test on the virtual network topology where the target network node is located, so as to obtain a penetration test result; on the basis of the penetration test result, determining an exploited network node, and on the basis of the vulnerability knowledge graph, determining remediation patch information, so as to remediate the exploited network node by using the remediation patch information; performing a virtual network penetration test on the exploited network node and the target network node, so as to obtain a post-remediation penetration test result; and on the basis of a comprehensive score corresponding to the post-remediation penetration test result and a comprehensive score corresponding to the penetration test result, respectively obtaining a vulnerability report and a defense report for the target network node.
Need to check novelty before this filing date? Find Prior Art

Description

Network testing method, device, electronic device, storage medium and program product Technical Field

[0001] The present application relates to the field of artificial intelligence technology, and in particular to a network testing method, device, electronic device, storage medium, and program product. Background Art

[0002] Currently, AI-based cyberattacks have become a new type of cyber threat, posing a significant threat to large-scale public networks. Leveraging methods such as reinforcement learning, automated information detection, vulnerability discovery, and exploitation can be achieved on target networks. These attacks are highly adaptive, difficult to detect, and challenging to defend against, significantly increasing the efficiency of penetration attacks.

[0003] With the continuous advancement of informatization and modernization in my country, cybersecurity issues are receiving widespread attention across all sectors of society. As a method for assessing network security, penetration testing utilizes specialized techniques and tools to simulate hackers probing, attacking, intruding, and maintaining presence in real-world network environments. This approach aims to identify vulnerabilities and ensure the relative security and stability of computer systems. Traditional penetration testing relies on complex manual operations performed by senior security experts with years of relevant experience, resulting in high time and labor costs.

[0004] In related technologies, the actual network topology is usually converted into an attack tree model, and deep reinforcement learning is used to find the most suitable network simulation attack path, and the path is automatically tested for network simulation penetration attack. However, there are problems in this method, such as ignoring the impact of network node patches on penetration testing, the constructed attack strategy map is not comprehensive enough, and the penetration test results obtained are not close to reality. Summary of the Invention

[0005] In view of this, the purpose of this application is to provide a network testing method, device, electronic device, storage medium and program product.

[0006] Based on the above objectives, in a first aspect, the present application provides a network testing method, the method comprising:

[0007] In response to triggering a node information change event, obtaining target network node information corresponding to the target network node, and determining a virtual network topology according to the target network node information;

[0008] Determine the target patch information and target vulnerability information corresponding to the target network node by using a vulnerability knowledge graph pre-built based on the patch information and vulnerability information corresponding to all network nodes;

[0009] Performing a virtual network penetration test on the virtual network topology where the target network node is located according to a preset network node reward and attack operation success rate to obtain a penetration test result;

[0010] Determining an exploited network node according to the penetration test result, and determining patch information for patching the exploited network node based on the vulnerability knowledge graph, so as to patch the exploited network node using the patch information;

[0011] Performing a virtual network penetration test on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information, based on a preset network node reward and attack operation success rate, to obtain a post-patch penetration test result;

[0012] In response to the difference between the comprehensive score corresponding to the penetration test result after the patch and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are respectively obtained based on the comprehensive score corresponding to the penetration test result after the patch and the comprehensive score corresponding to the penetration test result.

[0013] In a possible implementation, in response to triggering a node information change event, obtaining target network node information corresponding to the target network node includes:

[0014] In response to determining that a new network node exists, determining to trigger a node information change event, and obtaining target network node information corresponding to the target network node;

[0015] and / or,

[0016] In response to determining that a network node topology change event where the target network node is located is triggered, determining to trigger a node information change event, and acquiring target network node information corresponding to the target network node;

[0017] and / or,

[0018] In response to determining that a network node information change event corresponding to any network node in the network node topology where the target network node is located is triggered, determining to trigger the node information change event, and obtaining target network node information corresponding to the target network node;

[0019] and / or,

[0020] In response to receiving a reporting instruction indicating that a node information change event is triggered, it is determined that the node information change event is triggered, and target network node information corresponding to the target network node is acquired.

[0021] In a possible implementation, determining the virtual network topology according to the target network node information includes:

[0022] A topology relationship is obtained according to the target network node information based on the network element configuration link layer discovery protocol and the simple network management protocol, and the network node information is stored in the form of a management information base to determine the virtual network topology.

[0023] In a possible implementation, before using the vulnerability knowledge graph pre-built based on the patch information and vulnerability information corresponding to all network nodes, the method further includes:

[0024] Collect patch information and vulnerability information corresponding to all network nodes in the external database;

[0025] Determining a list of corresponding relationships between entities and entity attributes and a list of entity relationships based on the entities and entity attributes corresponding to all the network nodes; wherein the entities include: an operating system, enabled services and versions, enabled ports, vulnerabilities, and patches; and the list of entity relationships includes: a first entity relationship for illustrating an impact relationship between a vulnerability and the operating system, a second entity relationship for illustrating an utilization relationship between a vulnerability and enabled services and their versions, a third entity relationship for illustrating a threat relationship between a vulnerability and the operating system, a fourth entity relationship for illustrating a superior-subordinate relationship between vulnerabilities, a fifth entity relationship for illustrating a repair relationship between a patch and the operating system, a sixth entity relationship for illustrating an availability relationship between a patch and enabled services and their ports, and a seventh entity relationship for illustrating a defense relationship between the vulnerability and the patch;

[0026] A vulnerability knowledge graph is constructed based on the patch information, vulnerability information, the entity and entity attribute correspondence list, and the entity relationship list corresponding to all network nodes.

[0027] In a possible implementation, the list of correspondences between entities and entity attributes includes: correspondences between operating systems and operating system attributes, correspondences between enabled services and versions and enabled service and version attributes, correspondences between enabled ports and enabled port attributes, correspondences between vulnerabilities and vulnerability attributes, and correspondences between patches and patch attributes; wherein vulnerability attributes include: vulnerability number, vulnerability name, possibility of vulnerability exploitation, vulnerability impact score used to reflect the direct consequences of successful exploitation of the vulnerability, vulnerability exploitability score used to reflect the ease of exploitation of the vulnerability and the difficulty of technical means, vulnerability timing score evaluation index, vulnerability timing score used to reflect the characteristics of vulnerability vulnerability changing over time, vulnerability environment score evaluation index, vulnerability environment score used to represent the characteristics of vulnerability affected by user environment, vulnerability exploitation comprehensive coefficient, vulnerability concealment coefficient used to describe the concealment of the vulnerability, and average step length required to breach the vulnerability.

[0028] In a possible implementation, the vulnerability exploitation comprehensive coefficient includes: the exploitability of the vulnerability and the importance of the vulnerability;

[0029] The exploitability of the vulnerability is expressed as Vul_Exp=Vul_exploit_porb*Score_Base_Exploit

[0030] Among them, Vul_exploit_porb indicates the possibility of the vulnerability being exploited, and Score_Base_Exploit indicates the exploitability score of the vulnerability;

[0031] The importance of the vulnerability is expressed as Vul_Imp=α1*Score_Base_Impact+β1*Score_Term+γ1*Score_Env

[0032] Wherein, α1 represents the first weight, Score_Base_Impact represents the impact score of the vulnerability, β1 represents the second weight, Score_Term represents the time series score of the vulnerability, γ1 represents the third weight, Score_Env represents the environment score of the vulnerability;

[0033] The comprehensive coefficient of the vulnerability exploitation is expressed as Vul_Exp_Coeff=0.7*Vul_Exp+0.3*Vul_Imp.

[0034] In a possible implementation, the vulnerability timing score evaluation indicators include: vulnerability exploitation cost, patch level, and vulnerability confidence;

[0035] The timing score of the vulnerability is expressed as Score_Tem = (Score_Base_Impact + Score_Base_Exploit) * E * (1-RL) * RC

[0036] Wherein, E represents the cost of exploiting the vulnerability, RL represents the patch level, and RC represents the confidence level of the vulnerability.

[0037] In a possible implementation, the environmental score evaluation index of the vulnerability is expressed as Env_Index=Score_Tem*HID*TDR

[0038] Among them, HID represents the degree of hazard impact and TDR represents the target distribution range.

[0039] In a possible implementation, the attack operation success rate includes: a first attack operation success rate and a second attack operation success rate;

[0040] The performing of a virtual network penetration test on the virtual network topology where the target network node is located according to the preset network node reward and attack operation success rate to obtain a penetration test result includes:

[0041] Set the starting node reward value, target node reward value, vulnerability node reward value and honeypot node reward value; wherein, the vulnerability node reward value is expressed as Vul_score = α2*(Score_Base_Impact+Score_Base_Exploit) + β2*Score_Tem+γ2*Score_Env

[0042] Among them, α2 represents the fourth weight, β2 represents the fifth weight, and γ2 represents the sixth weight;

[0043] A first attack operation success rate for node vulnerability analysis and a second attack operation success rate for node defensiveness analysis are set, and the attack operation success rate is determined according to the first attack operation success rate and the second attack operation success rate; wherein the attack operation success rate is expressed as

[0044] The attacker is controlled to use a pre-trained reinforcement learning algorithm to attack the virtual network topology where the target network node is located based on the success rate of the first attack operation to obtain a first attack result, and the first node penetration test result is determined according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result according to the first attack result and the first node penetration test result; wherein the penetration test result includes: an attacker score, a penetration test path, a vulnerability concealment coefficient, an average attack step length, an exploited network node, and vulnerability information corresponding to the exploited network node; wherein the attacker score is expressed as Attack_score = ∑rewards-costs

[0045] Among them, rewards represents network node rewards, and costs represents attack costs.

[0046] In a possible implementation, after setting the first attack operation success rate for node vulnerability analysis and the second attack operation success rate for node defensiveness analysis, the method further includes:

[0047] The control attacker uses a pre-trained reinforcement learning algorithm to attack the virtual network topology of the exploited network node and the target network node after being patched with the patch information based on the success rate of the second attack operation to obtain a second attack result, and determines a second node penetration test result according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the post-patch penetration test result according to the second attack result and the second node penetration test result.

[0048] In a second aspect, the present application provides a network testing device, the device comprising:

[0049] a first determining module configured to, in response to a triggered node information change event, obtain target network node information corresponding to a target network node, and determine a virtual network topology according to the target network node information;

[0050] The second determination module is configured to determine target patch information and target vulnerability information corresponding to the target network node by using a vulnerability knowledge graph pre-constructed based on patch information and vulnerability information corresponding to all network nodes;

[0051] A first testing module is configured to perform a virtual network penetration test on the virtual network topology where the target network node is located according to a preset network node reward and an attack operation success rate to obtain a penetration test result;

[0052] a third determining module configured to determine an exploited network node according to the penetration test result, and determine patch information for patching the exploited network node based on the vulnerability knowledge graph, so as to patch the exploited network node using the patch information;

[0053] A second testing module is configured to perform a virtual network penetration test on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information, based on a preset network node reward and an attack operation success rate, to obtain a post-patch penetration test result;

[0054] The fourth determination module is configured to complete the patch test for the exploited network node in response to the difference between the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, and obtain a vulnerability report and a defensive report for the target network node according to the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result.

[0055] In a possible implementation, the first determining module is further configured to, in response to determining that a new network node exists, determine to trigger a node information change event, and obtain target network node information corresponding to the target network node;

[0056] and / or,

[0057] In response to determining that a network node topology change event where the target network node is located is triggered, determining to trigger a node information change event, and acquiring target network node information corresponding to the target network node;

[0058] and / or,

[0059] In response to determining that a network node information change event corresponding to any network node in the network node topology where the target network node is located is triggered, determining to trigger the node information change event, and obtaining target network node information corresponding to the target network node;

[0060] and / or,

[0061] In response to receiving a reporting instruction indicating that a node information change event is triggered, it is determined that the node information change event is triggered, and target network node information corresponding to the target network node is acquired.

[0062] In a possible implementation, the first determination module is further configured to obtain a topology relationship based on the target network node information based on the network element configuration link layer discovery protocol and simple network management protocol, and store the network node information in the form of a management information base to determine the virtual network topology.

[0063] In a possible implementation, the apparatus further includes: a construction module;

[0064] The building module is configured to collect patch information and vulnerability information corresponding to all network nodes in an external database;

[0065] Determining a list of corresponding relationships between entities and entity attributes and a list of entity relationships based on the entities and entity attributes corresponding to all the network nodes; wherein the entities include: an operating system, enabled services and versions, enabled ports, vulnerabilities, and patches; and the list of entity relationships includes: a first entity relationship for illustrating an impact relationship between a vulnerability and the operating system, a second entity relationship for illustrating an utilization relationship between a vulnerability and enabled services and their versions, a third entity relationship for illustrating a threat relationship between a vulnerability and the operating system, a fourth entity relationship for illustrating a superior-subordinate relationship between vulnerabilities, a fifth entity relationship for illustrating a repair relationship between a patch and the operating system, a sixth entity relationship for illustrating an availability relationship between a patch and enabled services and their ports, and a seventh entity relationship for illustrating a defense relationship between the vulnerability and the patch;

[0066] A vulnerability knowledge graph is constructed based on the patch information, vulnerability information, the entity and entity attribute correspondence list, and the entity relationship list corresponding to all network nodes.

[0067] In a possible implementation, the list of correspondences between entities and entity attributes includes: correspondences between operating systems and operating system attributes, correspondences between enabled services and versions and enabled service and version attributes, correspondences between enabled ports and enabled port attributes, correspondences between vulnerabilities and vulnerability attributes, and correspondences between patches and patch attributes; wherein vulnerability attributes include: vulnerability number, vulnerability name, possibility of vulnerability exploitation, vulnerability impact score used to reflect the direct consequences of successful exploitation of the vulnerability, vulnerability exploitability score used to reflect the ease of exploitation of the vulnerability and the difficulty of technical means, vulnerability timing score evaluation index, vulnerability timing score used to reflect the characteristics of vulnerability vulnerability changing over time, vulnerability environment score evaluation index, vulnerability environment score used to represent the characteristics of vulnerability affected by user environment, vulnerability exploitation comprehensive coefficient, vulnerability concealment coefficient used to describe the concealment of the vulnerability, and average step length required to breach the vulnerability.

[0068] In a possible implementation, the vulnerability exploitation comprehensive coefficient includes: the exploitability of the vulnerability and the importance of the vulnerability;

[0069] The exploitability of the vulnerability is expressed as Vul_Exp=Vul_exploit_porb*Score_Base_Exploit;

[0070] Among them, Vul_exploit_porb indicates the possibility of the vulnerability being exploited, and Score_Base_Exploit indicates the exploitability score of the vulnerability;

[0071] The importance of the vulnerability is expressed as Vul_Imp=α1*Score_Base_Impact+β1*Score_Term+γ1*Score_Env;

[0072] Among them, α1 represents the first weight, Score_Base_Impact represents the impact score of the vulnerability, β1 represents the second weight, Score_Term represents the time series score of the vulnerability, γ1 represents the third weight, Score_Env represents the environment score of the vulnerability ;

[0073] The comprehensive coefficient of the vulnerability exploitation is expressed as Vul_Exp_Coeff=0.7*Vul_Exp+0.3*Vul_Imp.

[0074] In a possible implementation, the vulnerability timing score evaluation indicators include: vulnerability exploitation cost, patch level, and vulnerability confidence;

[0075] The timing score of the vulnerability is expressed as Score_Tem=(Score_Base_Impact+Score_Base_Exploit)*E*(1-RL)*RC;

[0076] Wherein, E represents the cost of exploiting the vulnerability, RL represents the patch level, and RC represents the confidence level of the vulnerability.

[0077] In a possible implementation, the environmental score evaluation index of the vulnerability is expressed as Env_Index=Score_Tem*HID*TDR;

[0078] Among them, HID represents the degree of hazard impact and TDR represents the target distribution range.

[0079] In a possible implementation, the attack operation success rate includes: a first attack operation success rate and a second attack operation success rate;

[0080] The first test module is further configured to set a starting node reward value, a target node reward value, a vulnerability node reward value, and a honeypot node reward value; wherein the vulnerability node reward value is expressed as Vul_score = α2*(Score_Base_Impact+Score_Base_Exploit) + β2*Score_Tem+γ2*Score_Env

[0081] Among them, α2 represents the fourth weight, β2 represents the fifth weight, and γ2 represents the sixth weight;

[0082] A first attack operation success rate for node vulnerability analysis and a second attack operation success rate for node defensiveness analysis are set, and the attack operation success rate is determined according to the first attack operation success rate and the second attack operation success rate; wherein the attack operation success rate is expressed as

[0083] The attacker is controlled to use a pre-trained reinforcement learning algorithm to attack the virtual network topology where the target network node is located based on the success rate of the first attack operation to obtain a first attack result, and the first node penetration test result is determined according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result according to the first attack result and the first node penetration test result; wherein the penetration test result includes: an attacker score, a penetration test path, a vulnerability concealment coefficient, an average attack step length, an exploited network node, and vulnerability information corresponding to the exploited network node; wherein the attacker score is expressed as Attack_score = ∑rewards-costs

[0084] Among them, rewards represents network node rewards, and costs represents attack costs.

[0085] In one possible implementation, the second test module is further configured to control the attacker to use a pre-trained reinforcement learning algorithm to attack the virtual network topology of the exploited network node and the target network node after being patched with the patch information based on the success rate of the second attack operation to obtain a second attack result, and determine the second node penetration test result based on the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value to obtain the post-patch penetration test result based on the second attack result and the second node penetration test result.

[0086] In a third aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the test method as described in the first aspect when executing the program.

[0087] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the testing method as described in the first aspect.

[0088] In a fifth aspect, the present application provides a computer program product, comprising computer program instructions, which, when executed on a computer, cause the computer to execute the testing method as described in the first aspect.

[0089] From the above, it can be seen that the network testing method, device, electronic device, storage medium and program product provided by the present application obtain target network node information corresponding to the target network node in response to a triggered node information change event, and determine the virtual network topology based on the target network node information; use the vulnerability knowledge graph pre-constructed based on the patch information and vulnerability information corresponding to all network nodes to determine the target patch information and target vulnerability information corresponding to the target network node; perform a virtual network penetration test on the virtual network topology where the target network node is located based on the pre-set network node reward and attack operation success rate to obtain a penetration test result; determine the exploited network node based on the penetration test result, and determine the vulnerability for patching the target network node based on the vulnerability knowledge graph. The patch information of the exploited network node is obtained to patch the exploited network node using the patch information; according to the pre-set network node reward and attack operation success rate, a virtual network penetration test is performed on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information to obtain the post-patching penetration test result; in response to the difference between the comprehensive score corresponding to the post-patching penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are obtained according to the comprehensive score corresponding to the post-patching penetration test result and the comprehensive score corresponding to the penetration test result. This application can solve the problem of real-time changes in physical network node information, making the results of penetration testing more timely. The vulnerability situation is evaluated and a vulnerability knowledge graph is designed. The exploitability, importance, and defense measures of the vulnerability are described based on the designed knowledge graph, and patches and defense mechanisms are introduced in intelligent confrontation, so that the conclusions of intelligent confrontation are closer to reality. BRIEF DESCRIPTION OF THE DRAWINGS

[0090] In order to more clearly illustrate the technical solutions in this application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are merely embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0091] FIG1 shows a schematic diagram of an exemplary application scenario of a network testing method provided in an embodiment of the present application.

[0092] FIG2 shows a schematic diagram of an exemplary flow of a network testing method provided in an embodiment of the present application.

[0093] FIG3 shows an exemplary schematic diagram of a specific application scenario according to an embodiment of the present application.

[0094] FIG4 shows a schematic diagram of a test process in a specific application scenario according to an embodiment of the present application.

[0095] FIG5 shows an exemplary structural diagram of a network testing device provided in an embodiment of the present application.

[0096] FIG6 shows a schematic diagram of an exemplary structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0097] In order to make the objectives, technical solutions and advantages of this application more clear, this application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0098] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the usual meanings understood by people with ordinary skills in the field to which this application belongs. The "first", "second" and similar words used in the embodiments of the present application do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0099] The concept of "data governance" originated in the United States. The IBM (International Business Machines Corporation) Data Governance Committee has given a relevant definition of data governance: To realize corporate value, enterprises use a series of data management methods, management procedures, management indicators, and management roles throughout the entire cycle of data storage, data access, data use, data protection, and data verification to ensure that data is effectively developed and efficiently utilized. With the continuous development of power companies, the accumulation of assets, the increase in departments, and the refinement of professional divisions, the internal business data classification of enterprises has increased, resulting in serious data overlap and redundancy, making multimodal data difficult to maintain and quality assurance difficult. Therefore, in-depth research on comprehensive governance technologies for multimodal power samples is still needed.

[0100] As mentioned in the background section, AI-based cyberattacks are a new type of cyberthreat, posing a significant threat to large-scale, public networks. Leveraging methods like reinforcement learning, these attacks can automate information detection, vulnerability discovery, and exploitation within target networks. These attacks are highly adaptive, difficult to detect, and challenging to defend against, significantly increasing the effectiveness of penetration attacks.

[0101] With the continuous advancement of informatization and modernization in my country, cybersecurity issues are receiving widespread attention across all sectors of society. As a method for assessing network security, penetration testing utilizes specialized techniques and tools to simulate hackers probing, attacking, intruding, and maintaining presence in real-world network environments. This approach aims to identify vulnerabilities and ensure the relative security and stability of computer systems. Traditional penetration testing relies on complex manual operations performed by senior security experts with years of relevant experience, resulting in high time and labor costs.

[0102] Through the inventor's research, it was found that in some related technologies, the actual network topology is usually converted into an attack tree model, deep reinforcement learning is used to find the most suitable network simulation attack path, and the path is automatically tested for network simulation penetration attack. However, this intelligent penetration testing method based on reinforcement learning does not solve the problem of network node service changes and topology changes.

[0103] In other related technologies, the constructed attack strategy map can be used to quickly query the relevant information of the vulnerability, and then use the relevant information of the vulnerability to generate rich attack paths for penetration testing, thereby improving the efficiency of penetration testing. However, this intelligent penetration testing method does not solve the impact of network node patches on penetration testing, and the constructed attack strategy map is not comprehensive enough.

[0104] Other related technologies utilize a trained A3C model, input current vulnerability data, to generate a reward value, and then use this reward to select the optimal path. Finally, the optimal path derived from each round is used to generate a complete penetration test path. However, this method fails to consider the impact of network node patching on path selection.

[0105] Therefore, some related technologies have the problem of not being able to cope with changes in network node services and topology. The established attack tree model may lag behind, and the penetration test results obtained are not very timely. In other related technologies, the constructed attack strategy map ignores the impact of network node patches on penetration testing. The constructed attack strategy map is not comprehensive enough, and the penetration test results obtained are not in line with reality. In other related technologies, there are methods that derive reward values ​​from vulnerabilities and then select paths, which ignore the impact of network node patches on penetration testing. The penetration test results obtained are not in line with reality. In other words, existing technologies such as network scanning and penetration testing based on reinforcement learning lack description methods and update methods for real environments, real vulnerabilities and patch correction capabilities, or the methods have defects.

[0106] For this reason, the present application provides a network testing method, device, electronic device, storage medium and program product, which, in response to a triggered node information change event, obtains target network node information corresponding to the target network node, and determines a virtual network topology based on the target network node information; uses a vulnerability knowledge graph pre-constructed based on patch information and vulnerability information corresponding to all network nodes to determine target patch information and target vulnerability information corresponding to the target network node; performs a virtual network penetration test on the virtual network topology where the target network node is located based on a preset network node reward and attack operation success rate to obtain a penetration test result; determines the exploited network node based on the penetration test result, and determines a method for patching the exploited network node based on the vulnerability knowledge graph. Utilize the patch information of the network node to patch the exploited network node using the patch information; perform a virtual network penetration test on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information according to the preset network node reward and attack operation success rate, so as to obtain the post-patching penetration test result; in response to the difference between the comprehensive score corresponding to the post-patching penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are obtained according to the comprehensive score corresponding to the post-patching penetration test result and the comprehensive score corresponding to the penetration test result. This application can solve the problem of real-time changes in physical network node information, making the results of penetration testing more timely. Evaluate the vulnerability situation and design a vulnerability knowledge graph, describe the exploitability, importance, and defense measures of the vulnerability based on the designed knowledge graph, and introduce patches and defense mechanisms in intelligent confrontation, so that the conclusions of intelligent confrontation are closer to reality.

[0107] FIG1 shows a schematic diagram of an exemplary application scenario of a network testing method provided in an embodiment of the present application.

[0108] 1 , the application scenario includes a local terminal device 101 and a server 102. The local terminal device 101 and the server 102 may be connected via a wired or wireless communication network to achieve data interaction.

[0109] The local terminal device 101 can be an electronic device close to the user with data transmission and multimedia input / output functions, such as a desktop computer, mobile phone, mobile computer, tablet computer, media player, in-vehicle computer, smart wearable device, personal digital assistant (PDA), or other electronic device capable of implementing the above functions. The electronic device can include a processor and a display screen with touch input function, the display screen is used to present a graphical user interface, and the graphical user interface can display a user operation interface. The processor is used to process corresponding data, generate the graphical user interface, and control the display of the graphical user interface on the display screen.

[0110] Server 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms.

[0111] In some exemplary embodiments, the network testing method may be run on the local terminal device 101 or the server 102 .

[0112] When the network testing method is run on the server 102, the server 102 is used to provide network testing services to users of the terminal device. The terminal device is installed with a client that communicates with the server 102, and the user can specify the target program through the client. In response to the triggering of the node information change event, the server 102 obtains the target network node information corresponding to the target network node, and determines the virtual network topology based on the target network node information; uses the vulnerability knowledge graph pre-constructed based on the patch information and vulnerability information corresponding to all network nodes to determine the target patch information and target vulnerability information corresponding to the target network node; performs a virtual network penetration test on the virtual network topology where the target network node is located according to the pre-set network node reward and attack operation success rate to obtain the penetration test result; determines the exploited network node based on the penetration test result, and determines the patch information for patching the exploited network node based on the vulnerability knowledge graph, so as to facilitate The exploited network node is patched with the patch information; based on the preset network node reward and attack operation success rate, a virtual network penetration test is performed on the virtual network topology where the exploited network node and the target network node are located after being patched with the patch information to obtain a post-patch penetration test result; in response to the difference between the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are obtained respectively based on the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result. The server 102 can also send the vulnerability report and the defensive report to the client, and the client displays the vulnerability report and the defensive report to the user. The terminal device can be the local terminal device 101 mentioned above.

[0113] When the network testing method is run on the server 102 , the method can be implemented and executed based on a cloud interaction system.

[0114] Among them, the cloud interaction system includes client devices and cloud servers.

[0115] In some exemplary embodiments, the cloud interaction system can run various cloud applications, such as cloud gaming. Taking cloud gaming as an example, cloud gaming refers to a gaming method based on cloud computing. In the cloud gaming mode, the game program's execution and the game screen presentation are separate. The storage and execution of the in-game movement control methods are completed on the cloud gaming server. The client device is responsible for receiving and sending data and presenting the game screen. For example, the client device can be a display device with data transmission capabilities close to the user, such as a mobile terminal, television, computer, or PDA; however, the cloud gaming server in the cloud performs information processing. When playing the game, the player operates the client device to send operation instructions to the cloud gaming server. The cloud gaming server runs the game according to the operation instructions, encodes and compresses the game screen and other data, and returns it to the client device via the network. Finally, the client device decodes and outputs the game screen.

[0116] In the above embodiment, the network testing method is described by taking the network testing method running on the server 102 as an example. However, the present disclosure is not limited thereto. In some exemplary embodiments, the network testing method may also be run on the local terminal device 101 .

[0117] The local terminal device 101 may include a display screen and a processor. A client is installed in the local terminal device 101, and the user can specify the target program through the client. In response to triggering a node information change event, the processor obtains the target network node information corresponding to the target network node, and determines the virtual network topology based on the target network node information; uses the vulnerability knowledge graph pre-constructed based on the patch information and vulnerability information corresponding to all network nodes to determine the target patch information and target vulnerability information corresponding to the target network node; performs a virtual network penetration test on the virtual network topology where the target network node is located based on the pre-set network node reward and attack operation success rate to obtain a penetration test result; determines the exploited network node based on the penetration test result, and determines the patch information for patching the exploited network node based on the vulnerability knowledge graph to exploit the exploited network node. The patch information is used to patch the exploited network node; based on the preset network node reward and attack operation success rate, a virtual network penetration test is performed on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information to obtain a post-patch penetration test result; in response to the difference between the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are obtained respectively according to the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result. The processor can also send the vulnerability report and the defensive report to the client, and the client displays the vulnerability report and the defensive report to the user through a display screen.

[0118] For example, the local terminal device 101 may include a display screen and a processor, wherein the display screen is used to present a graphical user interface including an operation screen, and the processor is used to run the electronic system, generate the graphical user interface, and control the display of the graphical user interface on the display screen.

[0119] In some exemplary embodiments, the embodiments of the present disclosure provide a network testing method, providing a graphical user interface through a terminal device, wherein the terminal device can be the local terminal device 101 mentioned above, or can be a client device in the cloud interaction system mentioned above.

[0120] The following describes a test method according to an exemplary embodiment of the present disclosure in conjunction with the application scenario of Figure 1. It should be noted that the above application scenario is only shown to facilitate understanding of the spirit and principles of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.

[0121] FIG2 shows a schematic diagram of an exemplary flow of a network testing method provided in an embodiment of the present application.

[0122] Referring to FIG2 , an embodiment of the present application provides a network testing method, which specifically includes the following steps:

[0123] S202: In response to triggering a node information change event, obtaining target network node information corresponding to a target network node, and determining a virtual network topology according to the target network node information.

[0124] S204: Determine target patch information and target vulnerability information corresponding to the target network node using a vulnerability knowledge graph pre-constructed based on patch information and vulnerability information corresponding to all network nodes.

[0125] S206: Performing a virtual network penetration test on the virtual network topology where the target network node is located according to a preset network node reward and attack operation success rate to obtain a penetration test result.

[0126] S208: Determine the exploited network node according to the penetration test result, and determine patch information for patching the exploited network node based on the vulnerability knowledge graph, so as to patch the exploited network node using the patch information.

[0127] S210: Based on the preset network node reward and attack operation success rate, a virtual network penetration test is performed on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information to obtain a post-patch penetration test result.

[0128] S212: In response to the difference between the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are respectively obtained based on the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result.

[0129] In some embodiments, in response to determining that a new network node exists, a node information change event is determined to be triggered, and the target network node information corresponding to the target network node is obtained; and / or, in response to determining that a network node topology change event is triggered where the target network node is located, a node information change event is determined to be triggered, and the target network node information corresponding to the target network node is obtained; and / or, in response to determining that a network node information change event corresponding to any network node in the network node topology where the target network node is located is triggered, a node information change event is determined to be triggered, and the target network node information corresponding to the target network node is obtained; and / or, in response to receiving a reporting instruction indicating that a node information change event is triggered, a node information change event is determined to be triggered, and the target network node information corresponding to the target network node is obtained. That is, when a new node exists, node information changes, node topology changes, or a user-initiated reporting instruction is received, a node information change event is determined to be triggered.

[0130] In some embodiments, network node information can be obtained by installing an agent on a physical network node (computer, router, switch, printer, etc.). This agent can monitor network node information in real time. Network node information includes the host's operating system, subnet, IP address, enabled services and versions (stored in a list), enabled ports (stored in a list), host behavior, vulnerabilities, patches, virtual / physical hosts and their ID numbers. Specifically, the network node information can be represented as Info=<OS,subnets,IP,service / ver,port,action,vul,patch,host / id>

[0131] Among them, OS represents the operating system, subnets represents the subnet, IP represents the IP address, service / ver represents the enabled service and version, port represents the enabled port, action represents the host behavior, vul represents vulnerability information, patch represents the patch, and host / id represents the virtual / physical host and its ID number.

[0132] FIG3 shows an exemplary schematic diagram of a specific application scenario according to an embodiment of the present application.

[0133] Refer to Figure 3, the agent module: This module is software installed on the physical network node, which detects the status of the physical network node information and reports it to the topology management module. When the physical network node information changes, the agent module immediately and proactively reports the changed node information.

[0134] Topology management module: This module receives information from agent modules on multiple physical network nodes, supports manual generation of physical network topology, and supports manual initiation of agent module reporting instructions.

[0135] Patch information collection module: This module collects patch information corresponding to vulnerabilities in external databases.

[0136] Vulnerability information collection module: This module collects other information about vulnerabilities from external databases.

[0137] Vulnerability Knowledge Graph Module: Based on the information collected by the Patch Information Collection Module and the Vulnerability Information Collection Module, it integrates with external databases to build its own vulnerability knowledge graph. This module receives network node information provided by the Test Management Module, queries the vulnerability knowledge graph, obtains information about the node's vulnerability, patch, and other information, and transmits this information back to the Test Management Module for backup.

[0138] Test Management Module: This module virtualizes the physical network information transmitted from the Topology Management Module, constructs an intelligent penetration testing environment, and updates it in real time. This module transmits network node information to the Vulnerability Knowledge Graph Module. This module also receives information about vulnerabilities, patches, and other related information from the Vulnerability Knowledge Graph Module.

[0139] Intelligent Algorithm Management Module: This module manually selects a suitable reinforcement learning algorithm from the available reinforcement learning algorithms and hands it over to the intelligent infiltration module. The available reinforcement learning algorithms include: Q-Learning, DQN, DRQN, A3C, DDPG, and PPO.

[0140] Intelligent Penetration Module: This module receives the reinforcement learning algorithm selected by the Intelligent Algorithm Management Module and uses the intelligent agent to perform penetration testing on the intelligent penetration testing environment. Upon completion of the virtual network penetration test, a vulnerability report is generated and submitted to the Test Report Module. Upon completion of the virtual patch effectiveness assessment test, a defensive report is generated and submitted to the Test Report Module.

[0141] Test report module: receives vulnerability reports and defense reports from the intelligent penetration module, integrates them to generate a comprehensive report and presents it to the tester.

[0142] FIG4 shows a schematic diagram of a test process in a specific application scenario according to an embodiment of the present application.

[0143] Referring to Figure 4, agents on physical network nodes can monitor changes in network node information in real time. When new nodes are added to the physical network, information about existing nodes changes, or the network topology changes, the agent module reports the changed network node information to the topology management module. The topology management module supports manual initiation of agent module reporting commands.

[0144] Furthermore, the topology management module uses the Link Layer Discovery Protocol (LLDP) and Simple Network Management Protocol (SNMP) based on network element configuration to obtain topology relationships, stores network node information in the form of a Management Information Base (MIB), and automatically generates a virtual network topology. When the topology management module receives a node information change signal from the agent module, it supports manual modification of network node information.

[0145] Furthermore, the vulnerability knowledge graph module receives external information collected by the patch information collection module and the vulnerability information collection module, as well as manual input and correction data, to construct a vulnerability knowledge graph. Various values ​​in the vulnerability knowledge graph are updated in real time based on the network node information provided by the test management module.

[0146] Specifically, patch information and vulnerability information corresponding to all network nodes in an external database can be collected; a list of correspondences between entities and entity attributes and a list of entity relationships can be determined based on the entities and entity attributes corresponding to all network nodes; wherein the entities include: operating systems, enabled services and versions, enabled ports, vulnerabilities, and patches; the list of entity relationships includes: a first entity relationship for illustrating the impact relationship between vulnerabilities and operating systems, a second entity relationship for illustrating the utilization relationship between vulnerabilities and enabled services and their versions, a third entity relationship for illustrating the threat relationship between vulnerabilities and operating systems, a fourth entity relationship for illustrating the superior-subordinate relationship between vulnerabilities and vulnerabilities, a fifth entity relationship for illustrating the repair relationship between patches and operating systems, a sixth entity relationship for illustrating the availability relationship between patches and enabled services and their ports, and a seventh entity relationship for illustrating the defense relationship between vulnerabilities and patches; a vulnerability knowledge graph can be constructed based on the patch information, vulnerability information, the list of correspondences between entities and entity attributes, and the list of entity relationships corresponding to all network nodes.

[0147] The list of correspondences between entities and entity attributes includes: correspondences between operating systems and operating system attributes, correspondences between enabled services and versions and enabled service and version attributes, correspondences between enabled ports and enabled port attributes, correspondences between vulnerabilities and vulnerability attributes, and correspondences between patches and patch attributes; wherein, vulnerability attributes include: vulnerability number, vulnerability name, possibility of vulnerability exploitation, vulnerability impact score used to reflect the direct consequences of successful exploitation of the vulnerability, vulnerability exploitability score used to reflect the ease of exploitation of the vulnerability and the difficulty of technical means, vulnerability timing score evaluation index, vulnerability timing score used to reflect the characteristics of vulnerability vulnerability changing over time, vulnerability environment score evaluation index, vulnerability environment score used to represent the characteristics of vulnerability affected by user environment, vulnerability exploitation comprehensive coefficient, vulnerability concealment coefficient used to describe the concealment of the vulnerability, and average step length required to breach the vulnerability.

[0148] Specifically, the entity attribute list and entity relationship list are established as follows: wherein, the entity attribute list includes entities (operating system, enabled services and versions, enabled ports, vulnerabilities, patches) and corresponding notes and data types, as shown in Table 1.

[0149] Table 1 Entity attributes list

[0150] In some embodiments, the parameter Vul_Exp_Coeff represents the comprehensive probability of a vulnerability being exploited, which is composed of two parts: the exploitability of the vulnerability and the importance of the vulnerability.

[0151] The exploitability of the vulnerability is expressed as Vul_Exp=Vul_exploit_porb*Score_Base_Exploit

[0152] Among them, Vul_exploit_porb indicates the possibility of the vulnerability being exploited, and Score_Base_Exploit indicates the exploitability score of the vulnerability;

[0153] The importance of the vulnerability is expressed as Vul_Imp=α1*Score_Base_Impact+β1*Score_Term+γ1*Score_Env

[0154] Wherein, α1 represents the first weight, Score_Base_Impact represents the impact score of the vulnerability, β1 represents the second weight, Score_Term represents the time series score of the vulnerability, γ1 represents the third weight, Score_Env represents the environment score of the vulnerability;

[0155] The comprehensive coefficient of the vulnerability exploitation is expressed as Vul_Exp_Coeff=0.7*Vul_Exp+0.3*Vul_Imp.

[0156] Among them, α1=β1=γ1=0.33. If the value of the parameter RL in Tem_Index is greater than 0.25, then β1=0.4, α1=γ1=0.3.

[0157] The Tem_Index parameter is defined in Table 2. A larger value indicates a more significant meaning. This parameter requires manual selection by the operator.

[0158] Table 2 Parameter Tem_Index definition

[0159] The vulnerability's timing score evaluation indicators include: vulnerability exploitation cost, patch level, and vulnerability confidence; the vulnerability's timing score is expressed as Score_Tem = (Score_Base_Impact + Score_Base_Exploit) * E * (1-RL) * RC

[0160] Wherein, E represents the cost of exploiting the vulnerability, RL represents the patch level, and RC represents the confidence level of the vulnerability.

[0161] The definition of the parameter Env_Index is shown in Table 3. Both evaluation indicators are undefined by default, and the corresponding values ​​of each option are shown in the following table.

[0162] Table 3 Parameter Env_Index definition

[0163] The environmental score evaluation index of the vulnerability is expressed as Env_Index = Score_Tem*HID*TDR

[0164] Among them, HID represents the degree of hazard impact and TDR represents the target distribution range.

[0165] Table 4 shows the entity relationship list, which includes the relationship between vulnerability data and operating systems, enabled services and versions, and enabled ports, the relationship between vulnerabilities, the relationship between vulnerabilities and patches, the relationship between patches and operating systems, and the relationship between patches and services. "r" represents a relationship.

[0166] Table 4 Entity relationship list

[0167] In some embodiments, the test management module receives network node information and physical network topology information from the topology management module. The test management module sends the network node information to the vulnerability knowledge graph module. The vulnerability knowledge graph module sends the possible vulnerabilities and patch information of each network node to the test management module. Subsequently, the test management module establishes a virtual network topology and sends it to the intelligent penetration testing environment. The test management module queries the vulnerability knowledge graph through the network node information to obtain node vulnerabilities and patch information. The starting node reward value, target node reward value, vulnerability node reward value and honeypot node reward value are set, and the first attack operation success rate for node vulnerability analysis and the second attack operation success rate for node defensive analysis are set, and the attack operation success rate is determined based on the first attack operation success rate and the second attack operation success rate.

[0168] Among them, the network node reward setting rules are:

[0169] 1. The reward value of the starting node is 0, and the reward value of the target node is 100.

[0170] 2. For each vulnerable node, Vul_score is used as a reward score.

[0171] 3. The honeypot node reward value is -100.

[0172] Specifically, the vulnerability node reward value is expressed as Vul_score = α2*(Score_Base_Impact+Score_Base_Exploit) + β2*Score_Tem+γ2*Score_Env

[0173] Here, α2 represents the fourth weight, β2 represents the fifth weight, and γ2 represents the sixth weight.

[0174] In order to simulate the uncertainty of attacks in the real world, the attacker's attack operation in the intelligent penetration test has a certain success probability (Suc_prob). The success rate of each attack operation is defined by the following formula, where the first formula is the calculation method for the success rate of the first attack operation when performing node vulnerability analysis; the second formula is the calculation method for the success rate of the second attack operation after considering the impact of node patches when performing node defense analysis. The attack operation success rate is expressed as

[0175] The intelligent penetration module uses the reinforcement learning algorithm determined by the intelligent algorithm management module to perform virtual network penetration testing within the intelligent penetration testing environment. The attacker uses the trained reinforcement learning algorithm to launch an attack. The attacker's goal is to gain root directory access to vulnerable nodes. The penetration test results are recorded during the test. The results include the attacker's score (Attack_score), the vulnerability invisibility coefficient (Vul_Invisible_Coeff), the average attack step length (Vul_mean_step), and information about the exploited network nodes and vulnerabilities. Each attack operation is defined as having an attack cost of 1. The attacker's score is calculated using the Attack_score.

[0176] Specifically, the attacker is controlled to use a pre-trained reinforcement learning algorithm to attack the virtual network topology where the target network node is located based on the success rate of the first attack operation to obtain a first attack result, and the first node penetration test result is determined according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result according to the first attack result and the first node penetration test result; wherein, the penetration test result includes: attacker score, penetration test path, vulnerability concealment coefficient, average attack step length, exploited network node and vulnerability information corresponding to the exploited network node; wherein, the attacker score is expressed as Attack_score = ∑rewards-costs

[0177] Among them, rewards represents network node rewards, and costs represents attack costs.

[0178] The parameter vulnerability's invisibility coefficient Vul_Invisible_Coeff is represented by the frequency of the vulnerability being breached within the number of steps n in the round attack, Vul_Invisible_Coeff=q / m

[0179] Where q is the number of rounds in which the vulnerability is exploited within step number n in m rounds. The parameter Vul_mean_step is the average step length required to exploit the vulnerability in m rounds of attack.

[0180] After the virtual network penetration test is completed, the intelligent penetration module records the penetration results and transmits them to the test reporting module, generating a vulnerability report. The vulnerability report includes the virtual network penetration test attacker's score (Attack_score), the penetration test path, the average attack step length (Vul_mean_step), and vulnerability and patch information for each physical network node. The penetration test path is stored in a list format, with each element containing Info_host / id, Vul_id, and Vul_Invisible_Coeff. Vulnerability and patch information for each physical network node is obtained by querying the vulnerability knowledge graph using the physical network node information.

[0181] Furthermore, based on the exploited network nodes and vulnerabilities identified by the intelligent penetration module's virtual network penetration test, the system first obtains the exploited network node information. Based on the OS, service / ver, port, vul, and patch information in the node's Info, the system searches for a suitable patch from the vulnerability knowledge graph. The patch is then used to patch the exploited network node. The network node information in the test management module is manually modified, patch information is added, and the intelligent penetration test environment is regenerated.

[0182] The control attacker uses a pre-trained reinforcement learning algorithm to attack the virtual network topology of the exploited network node and the target network node after being patched with the patch information based on the success rate of the second attack operation to obtain a second attack result, and determines a second node penetration test result according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the post-patch penetration test result according to the second attack result and the second node penetration test result.

[0183] The intelligent penetration module uses the reinforcement learning algorithm determined by the intelligent algorithm management module to perform a virtual patching effectiveness evaluation test in the new intelligent penetration testing environment. After the virtual patching effectiveness evaluation test is completed, the intelligent penetration module records the penetration results (Attack score, Vul Invisible Coeff, Vul mean step, exploited network nodes and vulnerability information, etc.) and transmits them to the test reporting module.

[0184] The test report module collects information from the virtual patching effect evaluation test of the intelligent penetration module and generates a defensive report. The defensive report includes changes in the attacker's score Attack_score, the penetration test path, changes in the average attack step length Vul_mean_step, the vulnerabilities of each entity network node, and patch information. The penetration test path, the vulnerabilities of each entity network node, the patch information acquisition method, and the output format are the same as those of the vulnerability report. According to the comprehensive score corresponding to the penetration test result after the patch and the comprehensive score corresponding to the penetration test result, a vulnerability report and a defensive report for the target network node are obtained respectively. Specifically, the change in the attacker's score Attack_score is obtained by subtracting the attacker's score in the vulnerability report from the attacker's score in the virtual patching effect evaluation test. The change in the average attack step length Vul_mean_step is obtained by subtracting the average attack step length in the vulnerability report from the average attack step length in the virtual patching effect evaluation test.

[0185] This paper proposes a method and process for intelligent penetration testing using an agent to report network node information and topology changes, and automatically establish a virtual topology. The method and process contributed by this application can solve the problem of real-time changes in physical network node information, making the results of penetration testing more timely.

[0186] A method for establishing a vulnerability knowledge graph and evaluating and scoring the node vulnerability, attack overhead, vulnerability concealment, and attack operation success rate in the virtual network topology based on the graph.

[0187] Introduce patches and defense mechanisms in intelligent confrontation, record penetration results (attacker score Attack_score, vulnerability concealment coefficient Vul_Invisible_Coeff, attack average step length Vul_mean_step, exploited network nodes and vulnerability information, etc.) to conduct virtual patching effect evaluation test methods and processes.

[0188] From the above, it can be seen that the network testing method, device, electronic device, storage medium and program product provided by the present application obtain target network node information corresponding to the target network node in response to a triggered node information change event, and determine the virtual network topology based on the target network node information; use the vulnerability knowledge graph pre-constructed based on the patch information and vulnerability information corresponding to all network nodes to determine the target patch information and target vulnerability information corresponding to the target network node; perform a virtual network penetration test on the virtual network topology where the target network node is located based on the pre-set network node reward and attack operation success rate to obtain a penetration test result; determine the exploited network node based on the penetration test result, and determine the vulnerability for patching the target network node based on the vulnerability knowledge graph. The patch information of the exploited network node is obtained to patch the exploited network node using the patch information; according to the pre-set network node reward and attack operation success rate, a virtual network penetration test is performed on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information to obtain the post-patching penetration test result; in response to the difference between the comprehensive score corresponding to the post-patching penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, the patch test for the exploited network node is completed, and a vulnerability report and a defensive report for the target network node are obtained according to the comprehensive score corresponding to the post-patching penetration test result and the comprehensive score corresponding to the penetration test result. This application can solve the problem of real-time changes in physical network node information, making the results of penetration testing more timely. The vulnerability situation is evaluated and a vulnerability knowledge graph is designed. The exploitability, importance, and defense measures of the vulnerability are described based on the designed knowledge graph, and patches and defense mechanisms are introduced in intelligent confrontation, so that the conclusions of intelligent confrontation are closer to reality.

[0189] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario and performed by multiple devices working together. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the method.

[0190] It should be noted that the above description is limited to some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0191] FIG5 shows an exemplary structural diagram of a network testing device provided in an embodiment of the present application.

[0192] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a network testing device.

[0193] 5 , the network testing device includes: a first determining module, a second determining module, a first testing module, a third determining module, a second testing module, and a fourth determining module; wherein,

[0194] a first determining module configured to, in response to a triggered node information change event, obtain target network node information corresponding to a target network node, and determine a virtual network topology according to the target network node information;

[0195] The second determination module is configured to determine target patch information and target vulnerability information corresponding to the target network node by using a vulnerability knowledge graph pre-constructed based on patch information and vulnerability information corresponding to all network nodes;

[0196] A first testing module is configured to perform a virtual network penetration test on the virtual network topology where the target network node is located according to a preset network node reward and an attack operation success rate to obtain a penetration test result;

[0197] a third determining module, configured to determine an exploited network node according to the penetration test result, and determine patch information for patching the exploited network node based on the vulnerability knowledge graph;

[0198] A second testing module is configured to perform a virtual network penetration test on the virtual network topology where the exploited network node and the target network node are located after being patched using the patch information, based on a preset network node reward and an attack operation success rate, to obtain a post-patch penetration test result;

[0199] The fourth determination module is configured to complete the patch test for the exploited network node in response to the difference between the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, and obtain a vulnerability report and a defensive report for the target network node according to the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result.

[0200] In a possible implementation, the first determining module is further configured to:

[0201] In response to determining that a new network node exists, determining to trigger a node information change event, and obtaining target network node information corresponding to the target network node;

[0202] and / or,

[0203] In response to determining that a network node topology change event where the target network node is located is triggered, determining to trigger a node information change event, and acquiring target network node information corresponding to the target network node;

[0204] and / or,

[0205] In response to determining that a network node information change event corresponding to any network node in the network node topology where the target network node is located is triggered, determining to trigger the node information change event, and obtaining target network node information corresponding to the target network node;

[0206] and / or,

[0207] In response to receiving a reporting instruction indicating that a node information change event is triggered, it is determined that the node information change event is triggered, and target network node information corresponding to the target network node is acquired.

[0208] In a possible implementation, the first determining module is further configured to:

[0209] A topology relationship is obtained according to the target network node information based on the network element configuration link layer discovery protocol and the simple network management protocol, and the network node information is stored in the form of a management information base to determine the virtual network topology.

[0210] In a possible implementation, the second determining module is further configured to:

[0211] Collect patch information and vulnerability information corresponding to all network nodes in the external database;

[0212] Determining a list of corresponding relationships between entities and entity attributes and a list of entity relationships based on the entities and entity attributes corresponding to all the network nodes; wherein the entities include: an operating system, enabled services and versions, enabled ports, vulnerabilities, and patches; and the list of entity relationships includes: a first entity relationship for illustrating an impact relationship between a vulnerability and the operating system, a second entity relationship for illustrating an utilization relationship between a vulnerability and enabled services and their versions, a third entity relationship for illustrating a threat relationship between a vulnerability and the operating system, a fourth entity relationship for illustrating a superior-subordinate relationship between vulnerabilities, a fifth entity relationship for illustrating a repair relationship between a patch and the operating system, a sixth entity relationship for illustrating an availability relationship between a patch and enabled services and their ports, and a seventh entity relationship for illustrating a defense relationship between the vulnerability and the patch;

[0213] A vulnerability knowledge graph is constructed based on the patch information, vulnerability information, the entity and entity attribute correspondence list, and the entity relationship list corresponding to all network nodes.

[0214] In a possible implementation, the list of correspondences between entities and entity attributes includes: correspondences between operating systems and operating system attributes, correspondences between enabled services and versions and enabled service and version attributes, correspondences between enabled ports and enabled port attributes, correspondences between vulnerabilities and vulnerability attributes, and correspondences between patches and patch attributes; wherein vulnerability attributes include: vulnerability number, vulnerability name, possibility of vulnerability exploitation, vulnerability impact score used to reflect the direct consequences of successful exploitation of the vulnerability, vulnerability exploitability score used to reflect the ease of exploitation of the vulnerability and the difficulty of technical means, vulnerability timing score evaluation index, vulnerability timing score used to reflect the characteristics of vulnerability vulnerability changing over time, vulnerability environment score evaluation index, vulnerability environment score used to represent the characteristics of vulnerability affected by user environment, vulnerability exploitation comprehensive coefficient, vulnerability concealment coefficient used to describe the concealment of the vulnerability, and average step length required to breach the vulnerability.

[0215] In a possible implementation, the vulnerability exploitation comprehensive coefficient includes: the exploitability of the vulnerability and the importance of the vulnerability;

[0216] The exploitability of the vulnerability is expressed as Vul_Exp=Vul_exploit_porb*Score_Base_Exploit

[0217] Among them, Vul_exploit_porb indicates the possibility of the vulnerability being exploited, and Score_Base_Exploit indicates the exploitability score of the vulnerability;

[0218] The importance of the vulnerability is expressed as Vul_Imp=α1*Score_Base_Impact+β1*Score_Term+γ1*Score_Env

[0219] Wherein, α1 represents the first weight, Score_Base_Impact represents the impact score of the vulnerability, β1 represents the second weight, Score_Term represents the time series score of the vulnerability, γ1 represents the third weight, Score_Env represents the environment score of the vulnerability;

[0220] The comprehensive coefficient of the vulnerability exploitation is expressed as Vul_Exp_Coeff=0.7*Vul_Exp+0.3*Vul_Imp.

[0221] In a possible implementation, the vulnerability timing score evaluation indicators include: vulnerability exploitation cost, patch level, and vulnerability confidence;

[0222] The timing score of the vulnerability is expressed as Score_Tem = (Score_Base_Impact + Score_Base_Exploit) * E * (1-RL) * RC

[0223] Wherein, E represents the cost of exploiting the vulnerability, RL represents the patch level, and RC represents the confidence level of the vulnerability.

[0224] In a possible implementation, the environmental score evaluation index of the vulnerability is expressed as Env_Index=Score_Tem*HID*TDR

[0225] Among them, HID represents the degree of hazard impact and TDR represents the target distribution range.

[0226] In a possible implementation, the attack operation success rate includes: a first attack operation success rate and a second attack operation success rate;

[0227] The first test module is further configured to:

[0228] Set the starting node reward value, target node reward value, vulnerability node reward value and honeypot node reward value; wherein, the vulnerability node reward value is expressed as Vul_score = α2*(Score_Base_Impact+Score_Base_Exploit) + β2*Score_Tem+γ2*Score_Env

[0229] Among them, α2 represents the fourth weight, β2 represents the fifth weight, and γ2 represents the sixth weight;

[0230] A first attack operation success rate for node vulnerability analysis and a second attack operation success rate for node defensiveness analysis are set, and the attack operation success rate is determined according to the first attack operation success rate and the second attack operation success rate; wherein the attack operation success rate is expressed as

[0231] The attacker is controlled to use a pre-trained reinforcement learning algorithm to attack the virtual network topology where the target network node is located based on the success rate of the first attack operation to obtain a first attack result, and the first node penetration test result is determined according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result according to the first attack result and the first node penetration test result; wherein the penetration test result includes: an attacker score, a penetration test path, a vulnerability concealment coefficient, an average attack step length, an exploited network node, and vulnerability information corresponding to the exploited network node; wherein the attacker score is expressed as Attack_score = ∑rewards-costs

[0232] Among them, rewards represents network node rewards, and costs represents attack costs.

[0233] In a possible implementation, the second test module is further configured to:

[0234] The control attacker uses a pre-trained reinforcement learning algorithm to attack the virtual network topology of the exploited network node and the target network node after being patched with the patch information based on the success rate of the second attack operation to obtain a second attack result, and determines a second node penetration test result according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the post-patch penetration test result according to the second attack result and the second node penetration test result.

[0235] For the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing this application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0236] In another implementation example, the network testing device includes: a processor, wherein the processor is used to execute the program modules stored in the memory, including: a first determination module, a second determination module, a first test module, a third determination module, a second test module, and a fourth determination module.

[0237] The apparatus of the above embodiment is used to implement the corresponding network testing method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0238] FIG6 shows a schematic diagram of an exemplary structure of an electronic device provided in an embodiment of the present application.

[0239] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the network testing method described in any of the above embodiments when executing the program. FIG6 shows a more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment, which may include: a processor 610, a memory 620, an input / output interface 630, a communication interface 640, and a bus 650. The processor 610, the memory 620, the input / output interface 630, and the communication interface 640 are connected to each other within the device via the bus 650.

[0240] The processor 610 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0241] The memory 620 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 620 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 620 and is called and executed by the processor 610.

[0242] The input / output interface 630 is used to connect an input / output module to implement information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.

[0243] The communication interface 640 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).

[0244] The bus 650 comprises a pathway for transmitting information between the various components of the device, such as the processor 610 , the memory 620 , the input / output interface 630 , and the communication interface 640 .

[0245] It should be noted that although the above device only shows the processor 610, the memory 620, the input / output interface 630, the communication interface 640, and the bus 650, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.

[0246] The electronic device of the above embodiment is used to implement the corresponding network testing method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0247] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the network testing method described in any of the above embodiments.

[0248] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0249] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the network testing method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0250] Based on the same inventive concept, corresponding to the network testing method described in any of the above embodiments, the present disclosure further provides a computer program product comprising computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer to cause the computer and / or the processor to perform the network testing method. For the execution entities corresponding to the steps in each embodiment of the network testing method, the processors executing the corresponding steps can belong to the corresponding execution entities.

[0251] The computer program product of the above embodiment is used to enable the computer and / or the processor to execute the network testing method described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0252] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. Within the scope of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0253] In addition, for simplicity of description and discussion, and in order not to make the embodiment of the application difficult to understand, the known power supply / ground connection with integrated circuit (IC) chip and other components may or may not be shown in the accompanying drawings provided. In addition, the device can be shown in the form of a block diagram to avoid making the embodiment of the application difficult to understand, and this also takes into account the following fact, that is, the details of the embodiment of these block diagram devices are highly dependent on the platform to be implemented in the embodiment of the application (that is, these details should be fully within the scope of understanding of those skilled in the art). When specific details (for example, circuit) are set forth to describe exemplary embodiments of the application, it will be apparent to those skilled in the art that the embodiment of the application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.

[0254] Although the present invention has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may utilize the embodiments discussed.

[0255] The embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of this application.

Claims

1. A network testing method, characterized in that, The method includes: In response to a trigger for a node information change event, obtain the target network node information corresponding to the target network node, and determine a virtual network topology based on the target network node information; Using a vulnerability knowledge graph constructed in advance according to the patch information and vulnerability information corresponding to all network nodes, determine the target patch information and target vulnerability information corresponding to the target network node; Perform a virtual network penetration test on the virtual network topology where the target network node is located according to the pre-set network node rewards and the success rate of attack operations to obtain a penetration test result; Determine the exploited network node according to the penetration test result, and based on the vulnerability knowledge graph, determine the patch information for patching the exploited network node, so as to patch the exploited network node using the patch information; According to the pre-set network node rewards and the success rate of attack operations, perform a virtual network penetration test on the virtual network topology where the exploited network node and the target network node are located after patching using the patch information to obtain a post-patch penetration test result; In response to the difference between the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, complete the patching test for the exploited network node, and respectively obtain a vulnerability report and a defensive report for the target network node according to the comprehensive score corresponding to the post-patch penetration test result and the comprehensive score corresponding to the penetration test result.

2. The method according to claim 1, characterized in that, The "In response to a trigger for a node information change event, obtain the target network node information corresponding to the target network node" includes: In response to determining that there is a newly created network node, determine a trigger for a node information change event, and obtain the target network node information corresponding to the target network node; and / or In response to determining that a network node topology change event where the target network node is located is triggered, determine a trigger for a node information change event, and obtain the target network node information corresponding to the target network node; and / or In response to determining that a network node information change event corresponding to any network node in the network node topology where the target network node is located is triggered, determine a trigger for a node information change event, and obtain the target network node information corresponding to the target network node; and / or In response to receiving a reporting instruction indicating that a node information change event is triggered, determine a trigger for a node information change event, and obtain the target network node information corresponding to the target network node.

3. The method according to claim 1, wherein The "Determine a virtual network topology based on the target network node information" includes: Based on the network element configuration Link Layer Discovery Protocol and the Simple Network Management Protocol, obtain a topology relationship according to the target network node information, and store the network node information in the form of a Management Information Base to determine the virtual network topology.

4. The method according to claim 1, wherein Before using the vulnerability knowledge graph constructed in advance according to the patch information and vulnerability information corresponding to all network nodes, it further includes: Collect the patch information and vulnerability information corresponding to all network nodes in an external database; Determine the entity-entity attribute correspondence list and the entity relationship list according to the entities corresponding to all network nodes and the entity attributes; wherein, the entities include: operating system, enabled service and version, enabled port, vulnerability, and patch; the entity relationship list includes: a first entity relationship for explaining the impact relationship between a vulnerability and an operating system, a second entity relationship for explaining the exploitation relationship between a vulnerability and an enabled service and its version, a third entity relationship for explaining the threat relationship between a vulnerability and an operating system, a fourth entity relationship for explaining the hierarchical relationship between vulnerabilities, a fifth entity relationship for explaining the repair relationship between a patch and an operating system, a sixth entity relationship for explaining the availability relationship between a patch and an enabled service and its port, and a seventh entity relationship for explaining the defense relationship between a vulnerability and a patch; Construct a vulnerability knowledge graph according to the patch information, vulnerability information, the entity-entity attribute correspondence list, and the entity relationship list corresponding to all network nodes.

5. The method according to claim 4, wherein The entity-entity attribute correspondence list includes: the correspondence between an operating system and operating system attributes, the correspondence between an enabled service and version and enabled service and version attributes, the correspondence between an enabled port and enabled port attributes, the correspondence between a vulnerability and vulnerability attributes, and the correspondence between a patch and patch attributes; wherein, the vulnerability attributes include: vulnerability number, vulnerability name, possibility of the vulnerability being exploited, impact score of the vulnerability for reflecting the direct consequence caused by the successful exploitation of the vulnerability, exploitability score of the vulnerability for reflecting the ease of exploitation of the vulnerability and the difficulty level of technical means, time series score evaluation index of the vulnerability, time series score of the vulnerability for reflecting the characteristics of the vulnerability's vulnerability changing over time, environment score evaluation index of the vulnerability, environment score of the vulnerability for representing the characteristics of the vulnerability affected by the user environment, comprehensive exploitation coefficient of the vulnerability, concealment coefficient of the vulnerability for describing the concealment of the vulnerability, and average number of steps required for the vulnerability to be breached.

6. The method according to claim 5, characterized in that, The comprehensive exploitation coefficient of the vulnerability includes: the exploitability of the vulnerability and the importance of the vulnerability; Among them, the exploitability of the vulnerability is expressed as Vul_Exp = Vul_exploit_porb * Score_Base_Exploit; wherein, Vul_exploit_porb represents the possibility of the vulnerability being exploited, and Score_Base_Exploit represents the exploitability score of the vulnerability; The importance of the vulnerability is expressed as Vul_Imp = α1 * Score_Base_Impact + β1 * Score_Term + γ1 * Score_Env; wherein, α1 represents the first weight, Score_Base_Impact represents the impact score of the vulnerability, β1 represents the second weight, Score_Term represents the time series score of the vulnerability, γ1 represents the third weight, and Score_Env represents the environment score of the vulnerability; The comprehensive exploitation coefficient of the vulnerability is expressed as Vul_Exp_Coeff = 0.7 * Vul_Exp + 0.3 * Vul_Imp。 7. The method according to claim 6, characterized in that The time - series score evaluation metrics of the vulnerability include: the cost of vulnerability exploitation, the patch level, and the confidence level of the vulnerability; The time - series score of the vulnerability is expressed as Score_Tem = (Score_Base_Impact + Score_Base_Exploit) * E * (1 - RL) * RC; Where, E represents the cost of vulnerability exploitation, RL represents the patch level, and RC represents the confidence level of the vulnerability.

8. The method according to claim 7, wherein The environmental score evaluation metrics of the vulnerability are expressed as Env_Index = Score_Tem * HID * TDR; Where, HID represents the degree of harm impact, and TDR represents the target distribution range.

9. The method according to claim 7, characterized in that, The success rate of the attack operation includes: the first attack operation success rate and the second attack operation success rate; Performing virtual network penetration testing on the virtual network topology where the target network node is located according to the pre - set network node rewards and the success rate of the attack operation to obtain the penetration test result, including: Setting the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value; where, the vulnerability node reward value is expressed as Vul_score = α2 * (Score_Base_Impact + Score_Base_Exploit) + β2 * Score_Tem + γ2 * Score_Env Where, α2 represents the fourth weight, β2 represents the fifth weight, and γ2 represents the sixth weight; Set a first success rate of an attack operation for node vulnerability analysis and a second success rate of the attack operation for node defensive analysis, and determine the success rate of the attack operation according to the first success rate of the attack operation and the second success rate of the attack operation; wherein, the success rate of the attack operation is expressed as Controlling the attacker to use the pre - trained reinforcement learning algorithm to attack the virtual network topology where the target network node is located based on the first attack operation success rate to obtain the first attack result, and determining the first node penetration test result according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result according to the first attack result and the first node penetration test result; where, the penetration test result includes: the attacker's score, the penetration test path, the vulnerability concealment coefficient, the average attack step length, the exploited network nodes, and the vulnerability information corresponding to the exploited network nodes; where, the attacker's score is expressed as Attack_score = ∑rewards - costs Where, rewards represents the network node rewards, and costs represents the attack overhead.

10. The method according to claim 9, characterized in that, After setting the first attack operation success rate for node vulnerability analysis and the second attack operation success rate for node defensive analysis, it further includes: The control attacker uses a pre-trained reinforcement learning algorithm to attack the virtual network topology where the exploited network node and the target network node patched with the patch information are located based on the success rate of the second attack operation to obtain a second attack result, and determines a second node penetration test result according to the start node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the patched penetration test result according to the second attack result and the second node penetration test result.

11. A network testing device, characterized in that, The device includes: A first determination module, configured to, in response to a change event of trigger node information, obtain target network node information corresponding to a target network node, and determine a virtual network topology according to the target network node information; A second determination module, configured to use a vulnerability knowledge graph pre-constructed according to patch information and vulnerability information corresponding to all network nodes to determine target patch information and target vulnerability information corresponding to the target network node; A first test module, configured to perform a virtual network penetration test on the virtual network topology where the target network node is located according to a pre-set network node reward and attack operation success rate to obtain a penetration test result; A third determination module, configured to determine an exploited network node according to the penetration test result, and determine patch information for patching the exploited network node based on the vulnerability knowledge graph, so as to patch the exploited network node with the patch information; A second test module, configured to perform a virtual network penetration test on the virtual network topology where the exploited network node and the target network node patched with the patch information are located according to a pre-set network node reward and attack operation success rate to obtain a patched penetration test result; A fourth determination module, configured to, in response to the difference between the comprehensive score corresponding to the patched penetration test result and the comprehensive score corresponding to the penetration test result reaching a preset threshold, complete the patching test for the exploited network node, and obtain a vulnerability report and a defensive report for the target network node according to the comprehensive score corresponding to the patched penetration test result and the comprehensive score corresponding to the penetration test result respectively; 12. The device according to claim 11, wherein The first determination module is further configured to, in response to determining that there is a newly created network node, determine a change event of trigger node information, and obtain target network node information corresponding to the target network node; and / or In response to determining that a network node topology change event where the target network node is located is triggered, determine a change event of trigger node information, and obtain target network node information corresponding to the target network node; and / or In response to determining that a network node information change event corresponding to any network node in the network node topology where the target network node is located is triggered, determine a change event of trigger node information, and obtain target network node information corresponding to the target network node; and / or In response to receiving a reporting instruction for indicating that a node information change event is triggered, determine that the node information change event is triggered, and obtain the target network node information corresponding to the target network node.

13. The device according to claim 11, wherein, The first determination module is further configured to obtain a topological relationship based on the target network node information according to the network element configuration Link Layer Discovery Protocol (LLDP) and the Simple Network Management Protocol (SNMP), store the network node information in the form of a Management Information Base (MIB), and determine the virtual network topology.

14. The device according to claim 11, wherein The apparatus further includes: a construction module; The construction module is configured to collect patch information and vulnerability information corresponding to all network nodes in an external database; Determine a list of entity-entity attribute correspondence relationships and a list of entity relationships according to the entities and entity attributes corresponding to all network nodes; wherein the entities include: operating systems, enabled services and versions, enabled ports, vulnerabilities, and patches; the list of entity relationships includes: a first entity relationship for explaining the impact relationship between a vulnerability and an operating system, a second entity relationship for explaining the exploitation relationship between a vulnerability and an enabled service and its version, a third entity relationship for explaining the threat relationship between a vulnerability and an operating system, a fourth entity relationship for explaining the hierarchical relationship between vulnerabilities, a fifth entity relationship for explaining the repair relationship between a patch and an operating system, a sixth entity relationship for explaining the availability relationship between a patch and an enabled service and its port, and a seventh entity relationship for explaining the defense relationship between a vulnerability and a patch. Construct a vulnerability knowledge graph according to the patch information, vulnerability information, the list of entity-entity attribute correspondence relationships, and the list of entity relationships corresponding to all network nodes.

15. The device according to claim 14, characterized in that, The list of entity-entity attribute correspondence relationships includes: the correspondence relationship between an operating system and an operating system attribute, the correspondence relationship between an enabled service and its version and an enabled service and its version attribute, the correspondence relationship between an enabled port and an enabled port attribute, the correspondence relationship between a vulnerability and a vulnerability attribute, and the correspondence relationship between a patch and a patch attribute; wherein the vulnerability attributes include: vulnerability number, vulnerability name, probability of the vulnerability being exploited, impact score of the vulnerability for reflecting the direct consequence caused by the successful exploitation of the vulnerability, exploitability score of the vulnerability for reflecting the exploitable nature of the vulnerability and the difficulty level of technical means, temporal score evaluation index of the vulnerability, temporal score of the vulnerability for reflecting the characteristic of the vulnerability's vulnerability changing over time, environmental score evaluation index of the vulnerability, environmental score of the vulnerability for representing the characteristic of the vulnerability affected by the user environment, comprehensive exploitation coefficient of the vulnerability, concealment coefficient of the vulnerability for describing the concealment of the vulnerability, and average number of steps required for the vulnerability to be breached.

16. The device according to claim 15, characterized in that, The comprehensive exploitation coefficient of the vulnerability includes: the exploitability of the vulnerability and the importance of the vulnerability; wherein, the exploitability of the vulnerability is expressed as Vul_Exp = Vul_exploit_porb * Score_Base_Exploit; wherein, Vul_exploit_porb represents the probability of the vulnerability being exploited, and Score_Base_Exploit represents the exploitability score of the vulnerability. The importance of the vulnerability is expressed as Vul_Imp = α1 * Score_Base_Impact + β1 * Score_Term + γ1 * Score_Env; where α1 represents the first weight, Score_Base_Impact represents the impact score of the vulnerability, β1 represents the second weight, Score_Term represents the temporal score of the vulnerability, γ1 represents the third weight, and Score_Env represents the environmental score of the vulnerability; The comprehensive exploitation coefficient of the vulnerability is expressed as Vul_Exp_Coeff = 0.7 * Vul_Exp + 0.3 * Vul_Imp.

17. The device according to claim 16, characterized in that, The evaluation indicators of the temporal score of the vulnerability include: the cost of exploiting the vulnerability, the patch level, and the confidence level of the vulnerability; The temporal score of the vulnerability is expressed as Score_Tem = (Score_Base_Impact + Score_Base_Exploit) * E * (1 - RL) * RC; where E represents the cost of exploiting the vulnerability, RL represents the patch level, and RC represents the confidence level of the vulnerability.

18. The device according to claim 17, characterized in that, The evaluation indicator of the environmental score of the vulnerability is expressed as Env_Index = Score_Tem * HID * TDR; where HID represents the degree of harm and impact, and TDR represents the target distribution range.

19. The device according to claim 17, characterized in that, The success rate of the attack operation includes: the success rate of the first attack operation and the success rate of the second attack operation; The first test module is further configured to set the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value; where the vulnerability node reward value is expressed as Vul_score = α2 * (Score_Base_Impact + Score_Base_Exploit) + β2 * Score_Tem + γ2 * Score_Env where α2 represents the fourth weight, β2 represents the fifth weight, and γ2 represents the sixth weight; Set a first success rate of an attack operation for node vulnerability analysis and a second success rate of the attack operation for node defensive analysis, and determine the success rate of the attack operation according to the first success rate of the attack operation and the second success rate of the attack operation; wherein, the success rate of the attack operation is expressed as Control the attacker to use the pre-trained reinforcement learning algorithm to attack the virtual network topology where the target network node is located based on the success rate of the first attack operation to obtain a first attack result, and determine the first node penetration test result according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result according to the first attack result and the first node penetration test result; where the penetration test result includes: the attacker score, the penetration test path, the vulnerability concealment coefficient, the average attack step, the exploited network node, and the vulnerability information corresponding to the exploited network node; where the attacker score is expressed as Attack_score = ∑rewards - costs where rewards represents the network node reward and costs represents the attack overhead.

20. The device according to claim 19, wherein The second test module is further configured to control the attacker to use a pre-trained reinforcement learning algorithm to attack the virtual network topology where the exploited network node and the target network node patched with the patch information are located based on the success rate of the second attack operation to obtain a second attack result, and determine a second node penetration test result according to the starting node reward value, the target node reward value, the vulnerability node reward value, and the honeypot node reward value, so as to obtain the penetration test result after patching according to the second attack result and the second node penetration test result.

21. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and operable on the processor, characterized in that, When the processor executes the program, the method described in any one of claims 1-10 is implemented.

22. A computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to implement the method described in any one of claims 1-10.

23. A computer program product, characterized in that, It includes computer program instructions that, when the computer program instructions run on a computer, cause the computer to execute the method described in any one of claims 1-10.

Citation Information

Patent Citations

  • Automatic penetration testing method and device and electronic equipment

    CN114070632A

  • Vulnerability utilization relation determination method and device, equipment and storage medium

    CN114357189A

  • Automatic penetration testing method based on knowledge graph

    CN115883180A

  • Penetration testing method, device, equipment and medium

    CN116170224A

  • Network testing method and device, electronic equipment, storage medium and program product

    CN118041592A

Cited By

  • Computer network alarm system and method

    CN120512304A

  • Automatic penetration testing system, method and device, intelligent agent and storage medium

    CN120781367A

  • Web automatic penetration testing method and device, electronic equipment and storage medium

    CN120822223A

  • Assistant decision-making method, device and equipment for attack and defense drill scene and medium

    CN120825321A

  • Cloud platform vulnerability real-time quantitative analysis system based on dynamic knowledge graph

    CN121125242A