A cyberspace attack capability simulation method and device for weapon systems
By analyzing the attacking party's cyber attack equipment and using the threat attack behavior knowledge base, network attack cards and chains are built and simulations are carried out, the problem that the existing technology cannot effectively evaluate the cyber attack capabilities of high-capacity opponents is solved, and the authenticity and credibility of cyber-air security assessment is improved.
Patent Information
- Application Number
- CN202111597971.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-24
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-12-24
AI Technical Summary
The existing cyber-air security assessment methods cannot effectively infer and simulate the cyber attack capabilities of high-capacity opponents, resulting in untrue, incomplete and untrustworthy security assessment effects.
Through the analysis of the attacking party's cyber attack equipment, a network attack card is built, and a network attack chain is determined using the threat attack behavior knowledge base, and simulation is carried out to determine the cyber attack capabilities.
It realizes the real restoration of the cyber attack capabilities of high-capacity opponents and speculation on potential threats, and improves the authenticity, comprehensiveness and credibility of the cyber-air security confrontation capability assessment of weapon system.
Smart Images

Figure CN114254518B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a method and device for simulating cyberspace attack capabilities of a weapon system. Background Art
[0002] Military struggle is the most intense and comprehensive confrontation process. The cyber security of weapon systems will inevitably face long-term infiltration and attacks at the intelligence level and even the operational level of powerful enemies. Under such a cyber threat situation, any management procedures, technical mechanisms, and capability measures surrounding the cyber security of weapon systems, whether in terms of compliance certification or threat confrontation, should be placed in the context of strong enemy confrontation and tested in actual combat, so as to effectively evaluate their security effects and obtain true and credible evaluation conclusions. The existing commonly used cyber security assessment methods, such as network shooting ranges, generally have problems in the construction of the blue team, such as insufficient understanding of the tactical and technical systems of high-capability opponents, and inability to speculate and simulate the hidden tactical and technical capabilities of opponents, thus failing to ensure the authenticity, comprehensiveness and credibility of the security assessment results.
[0003] Therefore, studying the methods of constructing opponent tactics and technologies required for cyber security confrontation of weapon systems in the context of a strong enemy is a bottleneck that must be overcome and a capability that must be possessed in order to cope with modern and future multi-domain warfare conditions. Summary of the invention
[0004] In view of this, the present invention provides a method and device for simulating cyber attack capabilities of a weapon system, which simulate the network attack process of an attacker to determine the cyber attack capabilities of the attacker, thereby at least partially solving the problems existing in the prior art.
[0005] The specific content of the invention is:
[0006] A cyber attack capability simulation method for a weapon system, comprising:
[0007] Based on the analysis of the attacker's network attack equipment, construct a network attack card for the attacker;
[0008] Determine the network attack behavior of the attacker through the threat attack behavior knowledge base, and build the network attack chain of the attacker;
[0009] The network attack process of the attacker is simulated based on the network attack card and the network attack chain to determine the cyber attack capability of the attacker.
[0010] Furthermore, the analysis of the attacker's network attack equipment includes attack equipment analysis results, network threat intelligence and threat knowledge. The analysis of the attacker's network attack equipment specifically includes:
[0011] Determine the attacker's network attack equipment to be analyzed;
[0012] Analyze the equipment system and execution process of each network attack equipment to obtain the attack equipment analysis results;
[0013] Obtain cyber threat intelligence and threat knowledge involving the attacker;
[0014] The attack equipment analysis results, network threat intelligence and threat knowledge are used to construct the network attack card of the attacker.
[0015] Furthermore, the network attack card contains the attack technique and tactics information of the attacker, and the attack technique and tactics information includes: equipment name, department to which it belongs, equipment description, involved manufacturers, operating system targeted by the attack, and equipment operation mode.
[0016] Furthermore, determining the network attack process of the attacker through the threat attack behavior knowledge base and constructing the network attack chain of the attacker specifically includes:
[0017] The network attack process of the attacker is determined through the threat attack behavior knowledge base, the attack relationship mapping of the attacker is obtained, and the network attack chain of the attacker is constructed according to the attack relationship mapping.
[0018] Furthermore, the attack relationship mapping of the attacker includes a relationship mapping between the attack tactics and attack techniques of the attacker.
[0019] Further, according to the attack relationship mapping, a network attack chain of the attacker is constructed, which specifically includes:
[0020] Determining the network attack behavior of the attacker to be evaluated;
[0021] According to the relationship mapping between the attack tactics and the attack technology, mapping items of the attack tactics and the attack technology corresponding to the network attack behavior to be evaluated are obtained to obtain a sub-relationship mapping;
[0022] A network attack chain of the network attack behavior to be evaluated is constructed according to the sub-relationship mapping.
[0023] A cyberspace attack capability simulation device for a weapon system, comprising:
[0024] An attack card building module, used to build a network attack card of the attacker based on the analysis of the attacker's network attack equipment;
[0025] An attack chain building module, used to determine the network attack behavior of the attacker through a threat attack behavior knowledge base and build the network attack chain of the attacker;
[0026] The simulation module is used to simulate the network attack process of the attacker based on the network attack card and the network attack chain to determine the network attack capability of the attacker.
[0027] An electronic device, comprising: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside a space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the above-mentioned method.
[0028] A computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the above method.
[0029] A computer program product, when instructions in the computer program product are executed by a processor, performs the above method.
[0030] The beneficial effects of the present invention are embodied in:
[0031] The present invention constructs the attacker's network attack card and network attack chain based on the strong enemy equipment analysis and threat attack behavior knowledge base, simulates the attacker's network attack process on our military weapon system, and restores the attacker's real combat process, so as to fully grasp the attacker's combat capability and infer the attacker's potential threat, thus laying a reliable practical test foundation for the construction of cyberspace security of our military weapon system. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0033] Figure 1 This is a flow chart of a method for simulating cyberspace attack capability of a weapon system according to an embodiment of the present invention;
[0034] Figure 2 This is a flow chart of another method for simulating cyberspace attack capability of a weapon system according to an embodiment of the present invention;
[0035] Figure 3 This is a structural diagram of a cyberspace attack capability simulation device for a weapon system according to an embodiment of the present invention;
[0036] Figure 4The figure is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0037] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0038] It should be noted that the following embodiments and features in the embodiments may be combined with each other in the absence of conflict; and, based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making any creative work are within the scope of protection of the present disclosure.
[0039] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.
[0040] The present invention provides a method embodiment for simulating the cyberspace attack capability of a weapon system. Figure 1 As shown, including:
[0041] S11: Based on the analysis of the attacker's network attack equipment, construct a network attack card of the attacker;
[0042] S12: Determine the network attack behavior of the attacker through a threat attack behavior knowledge base, and construct a network attack chain of the attacker;
[0043] S13: Simulating the network attack process of the attacker based on the network attack card and the network attack chain to determine the cyber attack capability of the attacker.
[0044] In order to highly restore the real cyber-space attack capabilities and operational characteristics of potential adversaries, the present invention proposes an attack process simulation mechanism based on strong enemy equipment analysis and threat attack behavior knowledge base, infers the potential attack means and capability level of high-capability adversaries, and improves the authenticity, comprehensiveness and credibility of the cyber-space security confrontation capability assessment of weapon systems. The threat attack behavior knowledge base refers to ATT&CK (Adversarial Tactics Techniques & Common Knowledge), which is a knowledge base that widely collects adversary tactics and techniques based on real-world observations available worldwide. It solves technical problems such as how intruders enter the network environment, how to persist, and how to move laterally, and realizes the description of related factors such as the actions that intruders may take, and can clearly express various threats.
[0045] Preferably, the analysis of the attacker's network attack equipment includes attack equipment analysis results, network threat intelligence and threat knowledge. The analysis of the attacker's network attack equipment specifically includes:
[0046] Determine the network attack equipment of the attacker to be analyzed; analyze the equipment system and execution process of each network attack equipment to obtain the attack equipment analysis results; obtain network threat intelligence and threat knowledge involving the attacker; the attack equipment analysis results, network threat intelligence and threat knowledge are used to construct the network attack card of the attacker. Analyzing the network attack equipment of the attacker is a process with a large workload, so this process can be completed before executing the method of this embodiment, and the analysis results obtained after the analysis can be repeatedly used multiple times within a certain time limit, and the analysis data needs to be updated when it needs to be re-analyzed or incremental analysis can be performed on the original basis.
[0047] Preferably, the network attack card contains the attack technique and tactics information of the attacker, and the attack technique and tactics information includes: equipment name, department to which it belongs, equipment description, involved manufacturers, operating system targeted by the attack, and equipment operation mode.
[0048] During the experiment, the present invention sorted out the effective equipment of powerful enemies of various network powers, and some equipment information is shown in the following table. Based on the analysis of the equipment system and execution process of these equipment, as well as the acquisition of relevant threat intelligence resources and threat knowledge, a network attack card of a powerful enemy is constructed. The card data covers brief information on attack techniques and tactics such as equipment name, department, equipment description, equipment classification, involved manufacturers, operating system targeted by the attack, and equipment operation mode.
[0049]
[0050] Preferably, determining the network attack process of the attacker through the threat attack behavior knowledge base and constructing the network attack chain of the attacker specifically includes:
[0051] The network attack process of the attacker is determined through the threat attack behavior knowledge base, the attack relationship mapping of the attacker is obtained, and the network attack chain of the attacker is constructed according to the attack relationship mapping.
[0052] Preferably, the attack relationship mapping of the attacker includes the relationship mapping of the attacker's attack tactics and attack techniques. The attacker includes multiple attack tactics, such as "initial access", "execution", "persistence", etc. These attack tactics do not limit the time or order of execution, and the attacker can combine and run these attack tactics in any order. Under each attack tactic, multiple attack techniques used to support this attack tactic are included, such as, to achieve "initialization", "watering hole attack", "copying through removable media", "using spear phishing attachments" and other attack techniques can be run. The above-mentioned attack techniques also include sub-techniques of this attack technique. For example, "watering hole attack" includes sub-techniques "using downloaded files", "using Adobe Flash", "using various browser vulnerabilities", "using websites to obtain sensitive information". In addition, it also includes information closely related to the detection of this attack technique, such as data sources, and which APT organizations have adopted this attack technique and other technical details. All attack tactics and attack techniques are compiled into a knowledge base in the form of a matrix, namely the knowledge base of the ATT&CK framework. This knowledge base constitutes a relationship mapping between the attack tactics and attack techniques of the attacker. By extracting a series of attack tactics and the corresponding required attack techniques from this knowledge base, the attacker's network attack chain can be obtained.
[0053] In combination with the above examples, the attack chain constructed in the embodiment of the present invention is exemplified as follows:
[0054] Initial access (watering hole attack) - execution (execution through API) - persistence (manipulation of accounts - port probing - exploitation of system firmware) - lateral movement (copying remote files) - command and control (exploiting remote access tools) - impact (damaging firmware)
[0055] Preferably, according to the attack relationship mapping, constructing the network attack chain of the attacker specifically includes:
[0056] Determine the network attack behavior of the attacker to be evaluated; obtain the mapping items of attack tactics and attack techniques corresponding to the network attack behavior to be evaluated according to the relationship mapping of the attack tactics and attack techniques, and obtain a sub-relationship mapping; and construct a network attack chain of the network attack behavior to be evaluated according to the sub-relationship mapping.
[0057] The above preferred solution can correspond to the specified mapping items in the knowledge base matrix of the ATT&CK framework according to the attack techniques and tactics required for each threat assessment, forming a sub-relationship mapping corresponding to the threat, such as the X missile threat sub-relationship mapping and the X satellite threat sub-relationship mapping. The specific example is as follows: Based on the knowledge base matrix of the ATT&CK framework, a certain attack equipment X obtains a sub-relationship mapping according to the attack techniques and tactics required for a certain threat assessment, and the result is: Attack equipment X - ATT&CK threat framework {initial access [watering hole attack (using downloaded files, using Adobe Flash, exploit various browser vulnerabilities, exploit websites to obtain sensitive information)], execution [exploit host vulnerabilities (exploit system service vulnerabilities, exploit common protocol vulnerabilities, exploit office software vulnerabilities, exploit other third-party application vulnerabilities), scheduled tasks / jobs (exploit at.exe command program, exploit scheduled tasks, exploit Launchd execution, exploit Cron program execution)], privilege escalation [hijack execution process (DLL search order hijacking, DLL side loading, Dylib hijacking, hijacking binary files used by installers, LD_PRELOAD, service file exploitation, insufficient service registration center permissions)], defense evasion [process injection (dynamic link library injection, portable executable injection, thread execution hijacking, asynchronous procedure call, thread local storage, Ptrace system call, process memory, additional window memory injection, process flow, process hole, VDSO hijacking)], command and control [proxy (proxy, traffic redirection tool, external network proxy, multi-hop proxy, onion network)]}.
[0058] The present invention supports a series of configuration operations such as adding, deleting, modifying and checking attack techniques and tactics, thereby realizing adjustment and adaptation of attack techniques and tactics.
[0059] To further illustrate the present invention, in combination with the above preferred embodiments, another embodiment of a method for simulating the cyberspace attack capability of a weapon system is provided. Figure 2 As shown, including:
[0060] S21: Based on the analysis of the network attack equipment of the attacker, construct the network attack card of the attacker; the analysis of the network attack equipment of the attacker includes the analysis results of the attack equipment, network threat intelligence and threat knowledge. The analysis of the network attack equipment of the attacker specifically includes: determining the network attack equipment of the attacker to be analyzed; analyzing the equipment system and execution process of each network attack equipment to obtain the analysis results of the attack equipment; obtaining the network threat intelligence and threat knowledge related to the attacker; the attack equipment analysis results, network threat intelligence and threat knowledge are used to construct the network attack card of the attacker; the network attack card contains the attack technique and tactics information of the attacker, and the attack technique and tactics information includes: equipment name, department, equipment description, involved manufacturers, operating system targeted by the attack, and equipment operation mode;
[0061] S22: determining the network attack process of the attacker through the threat attack behavior knowledge base, and obtaining the attack relationship mapping of the attacker; the attack relationship mapping of the attacker includes the relationship mapping of the attack tactics and attack techniques of the attacker; the threat attack behavior knowledge base refers to the ATT&CK framework knowledge base;
[0062] S23: Determine the network attack behavior of the attacker to be evaluated;
[0063] S24: According to the relationship mapping between the attack tactics and the attack technology, mapping items of the attack tactics and the attack technology corresponding to the network attack behavior to be evaluated are obtained to obtain a sub-relationship mapping;
[0064] S25: constructing a network attack chain of the network attack behavior to be evaluated according to the sub-relationship mapping;
[0065] S26: Simulating the network attack process of the attacker based on the network attack card and the network attack chain to determine the cyber attack capability of the attacker.
[0066] Figure 2 The embodiment relies on the deep understanding of the network attack equipment system and operation methods, threat knowledge and intelligence resources of high-capability opponents to infer the potential attack means and capability level of high-capability opponents. With the fine-grained, richly combinable, comprehensive and highly realistic attack behavior knowledge base provided by ATT&CK, the cyberspace attack is structured and simulated. The attack process of high-capability opponents is significantly improved, and the authenticity, comprehensiveness and credibility of the weapon system cyberspace security confrontation capability assessment are significantly improved. Figure 2 The embodiment is based on Figure 1 The preferred solution of the embodiment is obtained, so Figure 2 The description of the above embodiment is relatively simple, and please refer to Figure 1 The embodiment described.
[0067] The present invention provides an embodiment of a network attack capability simulation device for a weapon system, such as Figure 3 As shown, including:
[0068] An attack card building module 31, used to build a network attack card of the attacker based on the analysis of the attacker's network attack equipment;
[0069] An attack chain building module 32, used to determine the network attack behavior of the attacker through a threat attack behavior knowledge base, and build a network attack chain of the attacker;
[0070] The simulation module 33 is used to simulate the network attack process of the attacker based on the network attack card and the network attack chain to determine the network attack capability of the attacker.
[0071] Preferably, the analysis of the attacker's network attack equipment includes attack equipment analysis results, network threat intelligence and threat knowledge. The analysis of the attacker's network attack equipment specifically includes:
[0072] Determine the network attack equipment of the attacker to be analyzed; analyze the equipment system and execution process of each network attack equipment to obtain the attack equipment analysis result; obtain network threat intelligence and threat knowledge related to the attacker; the attack equipment analysis result, network threat intelligence and threat knowledge are used to construct the network attack card of the attacker.
[0073] Preferably, the network attack card contains the attack technique and tactics information of the attacker, and the attack technique and tactics information includes: equipment name, department to which it belongs, equipment description, involved manufacturers, operating system targeted by the attack, and equipment operation mode.
[0074] Preferably, the attack chain building module 32 is specifically used for:
[0075] The network attack process of the attacker is determined through the threat attack behavior knowledge base, the attack relationship mapping of the attacker is obtained, and the network attack chain of the attacker is constructed according to the attack relationship mapping.
[0076] Preferably, the attack relationship mapping of the attacker includes a relationship mapping between the attack tactics and attack techniques of the attacker.
[0077] Preferably, according to the attack relationship mapping, constructing the network attack chain of the attacker specifically includes:
[0078] Determine the network attack behavior of the attacker to be evaluated; obtain the mapping items of attack tactics and attack techniques corresponding to the network attack behavior to be evaluated according to the relationship mapping of the attack tactics and attack techniques, and obtain a sub-relationship mapping; and construct a network attack chain of the network attack behavior to be evaluated according to the sub-relationship mapping.
[0079] Some processes of the device embodiment of the present invention are similar to those of the method embodiment. The description of the device embodiment is relatively simple, and please refer to the method embodiment for the corresponding parts.
[0080] The embodiment of the present invention further provides an electronic device, such as Figure 4 As shown, the present invention can be implemented Figure 1 , 2 In the process of the embodiment shown, the electronic device includes: a housing 41, a processor 42, a memory 43, a circuit board 44 and a power circuit 45, wherein the circuit board 44 is arranged inside the space enclosed by the housing 41, and the processor 42 and the memory 43 are arranged on the circuit board 44; the power circuit 45 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 43 is used to store executable program codes; the processor 42 runs the program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method described in the above-mentioned embodiment.
[0081] For details on the specific execution process of the above steps by the processor 42 and the steps further executed by the processor 42 by running the executable program code, please refer to the present invention. Figure 1 , 2 The description of the illustrated embodiment will not be repeated here.
[0082] An embodiment of the present invention further provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the method described in the above embodiment.
[0083] An embodiment of the present invention further provides a computer program product. When instructions in the computer program product are executed by a processor, the method described in the above embodiment is executed.
[0084] The present invention constructs the attacker's network attack card and network attack chain based on the knowledge base of powerful enemy equipment information and threat attack behavior, simulates the attacker's network attack process on our military weapon system, and restores the attacker's real combat process, so as to fully grasp the attacker's combat capability and infer the attacker's potential threat, thus laying a reliable practical test foundation for the construction of cyberspace security of our military weapon system.
[0085] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for simulating cyber attack capabilities of weapon systems. It is characterized in that include: Based on the analysis of the attacker's network attack equipment, construct a network attack card for the attacker; Determine the network attack behavior of the attacker through the threat attack behavior knowledge base, and build the network attack chain of the attacker; Simulating the network attack process of the attacker based on the network attack card and the network attack chain to determine the network attack capability of the attacker; The step of determining the network attack process of the attacker through the threat attack behavior knowledge base and constructing the network attack chain of the attacker includes: Determine the network attack process of the attacker through the threat attack behavior knowledge base, obtain the attack relationship mapping of the attacker, and construct the network attack chain of the attacker according to the attack relationship mapping; the attack relationship mapping of the attacker includes the relationship mapping of the attack tactics and attack techniques of the attacker; The step of constructing a network attack chain of the attacker according to the attack relationship mapping includes: Determining a network attack behavior of the attacker to be evaluated; the attacker corresponds to at least one network attack behavior; According to the relationship mapping between the attack tactics and the attack technology, the mapping items of the attack tactics and the attack technology corresponding to the network attack behavior to be evaluated are obtained to obtain a sub-relationship mapping; the attacker corresponds to at least one of the attack tactics, and the execution time and order of each of the attack tactics are determined by the network attack process; each of the attack tactics corresponds to at least one of the attack technologies, and each of the attack technologies corresponds to at least one sub-technology; the sub-relationship mapping is the relationship mapping between the attack tactics and the sub-technology corresponding to the network attack behavior of the attacker to be evaluated; the sub-relationship mapping corresponds to the relationship mapping between at least one attack tactic and the sub-technology; A network attack chain of the network attack behavior to be evaluated is constructed according to the sub-relationship mapping.
2. The method according to claim 1, It is characterized in that The analysis of the attacker's network attack equipment includes the attack equipment analysis results, network threat intelligence and threat knowledge. The analysis of the attacker's network attack equipment specifically includes: Determine the attacker's network attack equipment to be analyzed; Analyze the equipment system and execution process of each network attack equipment to obtain the attack equipment analysis results; Obtain cyber threat intelligence and threat knowledge involving the attacker; The attack equipment analysis results, network threat intelligence and threat knowledge are used to construct the network attack card of the attacker.
3. The method according to claim 2, It is characterized in that The network attack card contains the attack technique and tactics information of the attacker, and the attack technique and tactics information includes: equipment name, department, equipment description, involved manufacturers, operating system targeted by the attack, and equipment operation mode.
4. A cyber attack capability simulation device for weapon systems, It is characterized in that include: An attack card building module, used to build a network attack card of the attacker based on the analysis of the attacker's network attack equipment; An attack chain building module, used to determine the network attack behavior of the attacker through a threat attack behavior knowledge base and build the network attack chain of the attacker; Simulation, used to simulate the network attack process of the attacker based on the network attack card and the network attack chain, so as to determine the network attack capability of the attacker; The step of determining the network attack process of the attacker through the threat attack behavior knowledge base and constructing the network attack chain of the attacker includes: Determine the network attack process of the attacker through the threat attack behavior knowledge base, obtain the attack relationship mapping of the attacker, and construct the network attack chain of the attacker according to the attack relationship mapping; the attack relationship mapping of the attacker includes the relationship mapping of the attack tactics and attack techniques of the attacker; The step of constructing a network attack chain of the attacker according to the attack relationship mapping includes: Determining a network attack behavior of the attacker to be evaluated; the attacker corresponds to at least one network attack behavior; According to the relationship mapping between the attack tactics and the attack technology, the mapping items of the attack tactics and the attack technology corresponding to the network attack behavior to be evaluated are obtained to obtain a sub-relationship mapping; the attacker corresponds to at least one of the attack tactics, and the execution time and order of each of the attack tactics are determined by the network attack process; each of the attack tactics corresponds to at least one of the attack technologies, and each of the attack technologies corresponds to at least one sub-technology; the sub-relationship mapping is the relationship mapping between the attack tactics and the sub-technology corresponding to the network attack behavior of the attacker to be evaluated; the sub-relationship mapping corresponds to the relationship mapping between at least one attack tactic and the sub-technology; A network attack chain of the network attack behavior to be evaluated is constructed according to the sub-relationship mapping.
5. An electronic device, It is characterized in that The electronic device comprises: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute any method described in claims 1-3.
6. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method described in any one of claims 1-3.
7. A computer program product, It is characterized in that include: When the instructions in the computer program product are executed by a processor, the method according to any one of claims 1 to 3 is performed.
Citation Information
Patent Citations
Network attack and defense tool performance evaluation method and system based on a simulation platform
CN109583056A
Method and system for determining vulnerable points of network system and related components
CN109842632A
Network security vulnerability mining method and device
CN112187773A