A method, device, equipment and medium for network space security assessment and deduction of a weapon system
By adopting a hierarchical threat assessment and sand table deduction mode in weapon systems, the problem of network-air security assessment of weapon systems is solved, and a security closed loop for discovering and repairing security vulnerabilities is realized, and the network security and wartime efficiency of weapon systems are improved.
Patent Information
- Application Number
- CN202111596944.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-24
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-12-24
AI Technical Summary
The existing technology lacks effective methods and means to conduct cyber-air security assessment of weapon systems, resulting in serious constraints on the security and reliability of weapon systems in the face of cyber-air attacks.
A hierarchical threat assessment method based on basic static assessment, single-point threat assessment and attack chain threat assessment is adopted, and a sand table deduction model of the threat framework and cyberspace model is combined to comprehensively analyze the cyber-air security issues of the weapon system and discover vulnerable links and security vulnerabilities.
This method can effectively test and discover fragile links and security vulnerabilities in the cyber-air security of the weapon system, create a security closed loop from threat assessment to capability improvement, improve the network security of the weapon system, and ensure its wartime efficiency.
Smart Images

Figure CN114266052B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to a method, device, equipment and medium for cyber security assessment and deduction of weapon systems. Background Art
[0002] At all levels of ammunition, weapons, equipment, platforms, and systems, the cyber security issues involved in weapon systems are extremely diverse and complex, with prominent potential hidden dangers and vulnerabilities, and a large possible attack surface; there are not only the severe challenges of intelligence-level and combat-level attack operations from strong enemy opponents, but also various security risks that are difficult to anticipate and prevent due to factors such as the supply chain environment, maintenance mechanisms, and data exchange. As weapon systems become increasingly networked, the combat effectiveness of weapon systems increasingly depends on various information software and hardware, and the resulting automation and connectivity have become a powerful driving force for modern military capabilities. However, at the same time, this development trend also makes weapon systems more vulnerable to cyber attacks, thus seriously restricting the security and reliability of weapon systems, and even losing combat effectiveness in actual combat scenarios.
[0003] Although the cyberspace security of weapon systems has received high attention, up to now, there has been a lack of effective methods and feasible means for effectively evaluating the cyberspace security of weapon systems. Due to the high complexity of the composition, interaction, and dependency relationships of weapon systems themselves, their special cyberspace security attributes, and the operating scenarios, the cyberspace security of weapon systems not only faces general cyberspace security problems but also needs to solve deeper special problems. Generally speaking, the main reasons affecting the cyberspace security of weapon systems are as follows: First, while improving weapon performance by applying information technology and networking to form modern military capabilities, there is a lack of in-depth understanding and corresponding measures on how to develop more secure weapon systems; Second, the exponential growth of the number of software in weapon systems, the interconnection and information exchange between subsystems, the connection with external other systems for planning and executing tasks, and even the "air gap" systems that are not directly connected may all form or introduce various vulnerabilities, resulting in a significant increase in the cyberspace attack surface of weapon systems; Third, for a long time, the focus of cyberspace security has been on traditional information systems, and there is a general lack of attention to cyberspace security in the construction process of the entire weapon system. Cyberspace confrontation capabilities are not included in the most important capability indicators that weapon systems must meet, and there is also a lack of an effective cyberspace security testing mechanism for weapon systems. As a result, an entire generation of weapon systems has been designed and prepared without fully considering cyberspace security, which not only makes it extremely difficult to deploy cyberspace security for existing weapon systems but also has an associated impact on new weapon systems, resulting in almost all weapon systems lacking reliable cyberspace security capabilities; Fourth, given the many challenging difficulties in the cyberspace security requirements of weapon systems, it is difficult to adopt the same cyberspace security methods as traditional information technology systems in weapon systems. How to understand and enhance the cyberspace security of weapon systems, how to overcome the special difficulties in the cyberspace security defense of weapon systems, and how to effectively conduct systematic and comprehensive security testing and repair the existing security vulnerabilities in the huge and complex system of weapon systems all require pioneering exploration and persistent work in methods and means.
[0004] Looking at the current and future development situation of weapon systems, if the cyberspace security problems of weapon systems, especially the cyberspace security problems in the state of actual combat confrontation with strong enemies, cannot be effectively solved, it will seriously restrict the reliability and combat effectiveness of weapon systems in various combat domains. Therefore, studying the threat assessment and deduction method for the cyberspace security of weapon systems is a bottleneck that must be broken through and an ability that must be possessed under the conditions of modern and future multi-domain warfare. Summary of the Invention
[0005] In view of this, to partially solve the problems existing in the prior art, the present invention provides a method, device, equipment and medium for network space security assessment and deduction of a weapon system, adopting a hierarchical threat assessment method based on basic static assessment, single-point threat assessment and attack chain threat assessment and a threat deduction method under the sand table deduction mode, comprehensively analyzing the network space security problems of the weapon system from a single piece of equipment to an equipment system, effectively testing and discovering the vulnerable links and security loopholes in the network space security of the weapon system, and then creating a security closed-loop from threat assessment to capacity improvement, forming a technical support and traction mechanism for the construction of the network space security capacity of the weapon system.
[0006] The specific invention content is as follows:
[0007] A method for network space security assessment and deduction of a weapon system, comprising:
[0008] Abstractly model the network space of the weapon system to obtain a network space model of the weapon system;
[0009] Conduct a basic static assessment of the network security of the network space model, conduct single-point threat assessment and attack chain threat assessment on the network space model through a threat framework, summarize the assessment results, and output an assessment report;
[0010] Combined with the assessment report, deduce the offense and defense process of the network space of the weapon system based on the threat framework and the network space model to determine the security risks of the network space of the weapon system.
[0011] Further, conducting a single-point threat assessment on the network space model through a threat framework specifically includes:
[0012] Determine the threat behaviors for single-point threat assessment through the threat framework, conduct simulated attacks on the network space model through the threat behaviors, obtain the attack responses of the network space model, and use them to evaluate the defense capabilities of the network space model to respond to the corresponding threat behaviors.
[0013] Further, conducting an attack chain threat assessment on the network space model through a threat framework specifically includes:
[0014] Determine the attack sequences for attack chain threat assessment through the threat framework, conduct simulated attacks on the network space model through the attack sequences, obtain the attack responses of the network space model, and use them to evaluate the defense capabilities of the network space model to respond to the corresponding attack sequences.
[0015] Further, the assessment report includes the vulnerabilities, attackable points, network space attack exposure surface, and recommended reinforcement measures of the network space model.
[0016] Further, the deduction process of the offensive and defensive operations in the cyber space of the weapon system is realized through a threat deduction system, and the threat deduction system includes:
[0017] A director module, which is used to send deduction instructions to the attacker module and manage the entire cycle of the offensive and defensive deduction;
[0018] An attacker module, which is used to receive the deduction instructions sent by the director module and perform a simulated attack on the cyber space model according to the threat framework;
[0019] A defender module, which is used to combine the evaluation report and carry out defensive responses to the specific simulated attacks executed by the attacker module.
[0020] Further, the director module is specifically used for:
[0021] Generate an offensive and defensive deduction script according to preset rules and obtain an offensive and defensive deduction task;
[0022] Generate deduction instructions according to the offensive and defensive deduction task and send them to the attacker module;
[0023] Manage the entire cycle of each stage of the offensive and defensive deduction; each stage of the offensive and defensive deduction includes: not started stage, preparatory stage, confrontation stage, summary stage, and ended stage.
[0024] Further, the attacker module is specifically used for:
[0025] In the preparatory stage, receive the deduction instructions sent by the director module, obtain the corresponding attack chain in the threat framework according to the deduction instructions, and configure attack cards for each node of the attack chain;
[0026] In the confrontation stage, submit the attack chain to the director module and perform a simulated attack on the cyber space model through the attack chain.
[0027] Further, the defender module is specifically used for:
[0028] In the preparatory stage, strengthen the defense of the cyber space model according to the evaluation report;
[0029] In the confrontation stage, check the defense reinforcement situation of the specific strike positions of the attack cards, and match the corresponding defense strategies or make attack responses according to the check situation.
[0030] Further, the director module is also used for:
[0031] Adjust the offensive and defensive deduction script and the offensive and defensive deduction task in the not started stage according to the change of the preset rules;
[0032] During the confrontation stage, receive the attack chain sent by the attacker module, and monitor the attack and defense deduction process of the attacker module and the defender module according to the attack chain to determine the situation of the attack and defense deduction.
[0033] During the summary stage, obtain the network space security risk points of the weapon system and the corresponding reinforcement and adjustment opinions according to the monitoring situation during the confrontation stage.
[0034] Further, monitoring the attack and defense deduction process of the attacker module and the defender module according to the attack chain specifically includes:
[0035] Monitor the simulated attack situation of each attack card according to the attack chain. When a simulated attack is carried out through an attack card, if the simulated attack is successful or the defender module does not make an attack response, it is determined that there is a security risk at the specific position of the cyber space model attacked by the attack card.
[0036] A cyber security assessment and deduction device for a weapon system includes:
[0037] A cyber space model construction module for abstractly modeling the cyber space of the weapon system to obtain a cyber space model of the weapon system.
[0038] A threat assessment module for performing a basic static assessment of the network security of the cyber space model, performing a single-point threat assessment and an attack chain threat assessment on the cyber space model through a threat framework, summarizing the assessment results, and outputting an assessment report.
[0039] An attack and defense deduction module for combining the assessment report and deducing the attack and defense process of the cyber space of the weapon system based on the threat framework and the cyber space model to determine the security risk of the cyber space of the weapon system.
[0040] An electronic device includes a housing, a processor, a memory, a circuit board, and a power supply circuit. Among them, the circuit board is arranged inside the space surrounded by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to each circuit or device of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs the program corresponding to the executable program codes by reading the executable program codes stored in the memory and is used to execute the foregoing method.
[0041] A computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the foregoing method.
[0042] The beneficial effects of the present invention are as follows:
[0043] The present invention focuses on the evaluation of the cyberspace security capabilities of weapon systems and solves the fundamental problems restricting the cyberspace security of weapon systems. It adopts a hierarchical threat assessment method based on basic static assessment, single-point threat assessment, and attack chain threat assessment, as well as a threat deduction method under the sand table deduction mode. It comprehensively studies the cyberspace security issues of weapon systems from single equipment to equipment systems, effectively tests and discovers the vulnerable links and security loopholes in the cyberspace security of weapon systems, and then creates a security closed-loop from threat assessment to capacity improvement, forming a technical support and traction mechanism for the construction of the cyberspace security capabilities of weapon systems. The present invention is fundamental and general, and can be replicated and promoted in various stages such as the design, research and development, application, support, and retirement of various types of weaponry in our military, improving the network security of various types of weapon systems in our military and ensuring the combat effectiveness of weapon systems. In addition, the present invention can also be popularized and applied in the network security assessment, network security protection solution design, network security reinforcement, etc. of various key information infrastructures and important information systems such as energy, medical care, communication, and finance, and has broad application prospects. Brief Description of the Drawings
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0045] Figure 1 It is a flowchart of a method for evaluating and deducing the cyberspace security of a weapon system according to an embodiment of the present invention;
[0046] Figure 2 It is a schematic diagram of a threat deduction system according to an embodiment of the present invention;
[0047] Figure 3 It is another flowchart of a method for evaluating and deducing the cyberspace security of a weapon system according to an embodiment of the present invention;
[0048] Figure 4 It is a structural diagram of a device for evaluating and deducing the cyberspace security of a weapon system according to an embodiment of the present invention;
[0049] Figure 5 It is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Embodiments
[0050] The embodiments of the present invention will be described in detail below with reference to the drawings.
[0051] It should be noted that the following embodiments and features in the embodiments may be combined with each other in the absence of conflict; and, based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making any creative work are within the scope of protection of the present disclosure.
[0052] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.
[0053] The present invention provides a method embodiment for evaluating and simulating cyberspace security of a weapon system. Figure 1 As shown, including:
[0054] S11: Abstract modeling of the weapon system cyberspace is performed to obtain a weapon system cyberspace model;
[0055] S12: Performing a basic static assessment on the network security of the cyberspace model, and performing a single-point threat assessment and an attack chain threat assessment on the cyberspace model through a threat framework;
[0056] S13: Summarize the evaluation results and output the evaluation report;
[0057] S14: In combination with the assessment report, the attack and defense process of the weapon system cyberspace is deduced based on the threat framework and the cyberspace model to determine the security risk of the weapon system cyberspace.
[0058] In view of the high complexity of the composition, interaction and dependence of weapon systems themselves, their special cyberspace security attributes and application scenarios, there has always been a lack of effective methods and feasible means for network security assessment. Therefore, a hierarchical threat assessment method based on basic static assessment, single-point threat assessment and attack chain threat assessment, and a threat deduction method under the sand table mode based on threat frameworks and cyberspace models are creatively proposed to determine the security risks in the cyberspace of the weapon system and solve the fundamental problems restricting the cyberspace security of weapon systems. The threat framework is obtained based on accumulated known threat behaviors or an existing threat attack behavior knowledge base, and the threat framework contains descriptions of attack behaviors that can pose threats to the cyberspace of weapon systems. Among them, the threat attack behavior knowledge base preferably uses ATT&CK (Adversarial Tactics Techniques & Common Knowledge). ATT&CK is a knowledge base that widely collects the tactics and techniques of opponents based on real-world observations globally, solves technical problems such as how intruders enter the internal network environment, how to achieve persistence, lateral movement, etc., realizes the description of relevant factors such as the possible actions that intruders may take, and can clearly express various threats.
[0059] Preferably, a single-point threat assessment is performed on the cyberspace model through the threat framework, which specifically includes:
[0060] Determine the threat behaviors for single-point threat assessment through the threat framework, and perform a simulated attack on the cyberspace model through the threat behaviors to obtain the attack response of the cyberspace model, so as to evaluate the defense ability of the cyberspace model to cope with the corresponding threat behaviors. This process supports selecting a specific threat step or behavior in the cyberspace threat framework for targeted assessment and response, and mainly uses a semi-automated or human-computer interaction method to achieve single-point threat assessment.
[0061] Preferably, an attack chain threat assessment is performed on the cyberspace model through the threat framework, which specifically includes:
[0062] Determine the attack sequence for attack chain threat assessment through the threat framework, and perform a simulated attack on the cyberspace model through the attack sequence to obtain the attack response of the cyberspace model, so as to evaluate the defense ability of the cyberspace model to cope with the corresponding attack sequence. This process supports evaluating a specific attack sequence and mainly uses a semi-automated or human-computer interaction method to achieve attack chain threat assessment.
[0063] Preferably, the assessment report includes the vulnerabilities, attackable points, cyber-attack exposure surface of the cyberspace model, and recommended reinforcement measures. It supports outputting the threat assessment results in the form of a report, covering information such as the cyber-attack exposure surface, vulnerabilities, attackable points of the weapon system, and recommended reinforcement measures adapted to the cyber model of the weapon system, facilitating reference in subsequent offense-defense deduction processes.
[0064] Preferably, the offense-defense deduction process of the weapon system's cyberspace is realized through a threat deduction system, and the threat deduction system includes:
[0065] A director module, used to send deduction instructions to the attacker module and manage the entire cycle of the offense-defense deduction;
[0066] An attacker module, used to receive the deduction instructions sent by the director module and simulate attacks on the cyberspace model according to the threat framework;
[0067] A defender module, used to combine the assessment report and defend against the specific simulated attacks executed by the attacker module.
[0068] Preferably, the director module is specifically used for:
[0069] Generating an offense-defense deduction scenario according to preset rules and obtaining an offense-defense deduction task;
[0070] Generating deduction instructions according to the offense-defense deduction task and sending them to the attacker module;
[0071] Managing the entire cycle of each stage of the offense-defense deduction; each stage of the offense-defense deduction includes: not started stage, preparatory stage, confrontation stage, summary stage, and ended stage.
[0072] Preferably, the attacker module is specifically used for:
[0073] In the preparatory stage, receiving the deduction instructions sent by the director module, obtaining the corresponding attack chain in the threat framework according to the deduction instructions, and configuring attack cards for each node of the attack chain;
[0074] In the confrontation stage, submitting the attack chain to the director module and simulating attacks on the cyberspace model through the attack chain.
[0075] Preferably, the defender module is specifically used for:
[0076] In the preparatory stage, strengthening the defense of the cyberspace model according to the assessment report;
[0077] During the confrontation stage, verify the defense reinforcement of the specific attack position of the attack card, and match the corresponding defense strategy or perform an attack response according to the verification result.
[0078] Preferably, the director module is further configured to:
[0079] Adjust the attack and defense deduction script and the attack and defense deduction task during the not-yet-started stage according to the change of the preset rules;
[0080] During the confrontation stage, receive the attack chain sent by the attacker module, and monitor the attack and defense deduction process of the attacker module and the defender module according to the attack chain, so as to judge the situation of the attack and defense deduction;
[0081] During the summary stage, obtain the network space security risk points of the weapon system and the corresponding reinforcement and adjustment opinions according to the monitoring situation during the confrontation stage.
[0082] Preferably, monitoring the attack and defense deduction process of the attacker module and the defender module according to the attack chain specifically includes:
[0083] Monitor the simulated attack situation of each attack card according to the attack chain. When a simulated attack is carried out through an attack card, if the simulated attack is successful or the defender module does not perform an attack response, it is determined that there is a security risk at the specific position of the network space model attacked by the attack card.
[0084] To further illustrate the threat deduction system in the above embodiments, a schematic diagram of the threat deduction system is provided, as Figure 2As shown in the figure. The threat deduction system includes an attacker module, a defender module, and a director module. The attacker module provides functions such as threat framework management, attack card management, and attack link management. The defender module provides functions such as network space model solid defense and defense confrontation response. The director module provides management of deduction scripts, deduction tasks, deduction processes, and the generation of deduction reports. The director module writes a script through deduction script management according to preset rules, and initiates a deduction by creating a deduction task. The status of the deduction task is divided into five stages: not started, preparatory period, confrontation period, summary period, and ended. The functions of different modules will have certain distinctions in each stage. The not started stage is the default state after the director creates a deduction task. In this stage, it supports modifying the deduction script, modifying deduction task information and participants, etc. through deduction script management and deduction task management; after the deduction task starts, it enters the preparatory period. In the preparatory period, the attacker module can directly select existing frameworks in the threat framework or extract attack sequences as needed, arrange the attack links of the network space model according to the tactics and techniques in the threat framework, and prepare attack cards at each link node. The defender module can perform defense reinforcement on the entities in the network space model according to the evaluation report; after the preparatory period ends, it switches to the confrontation period. In the confrontation period, the attacker module submits the link, and both the attacker and the defender conduct offense and defense confrontation based on each node in the link, that is, the attack card. During the deduction process, the attacker module can manage information such as the threat framework and attack cards, and construct the operation link for the network space model of the weapon system based on the tactical and technical points of the threat framework. The defender module can further reinforce the resources in the network space model to counter threat attacks. The director module manages the entire deduction process and determines the offense and defense deduction situation; in the summary period, it can automatically mark the exposed surfaces, vulnerability points, and attack points on each entity in the network space model, and initially form an automated reinforcement adjustment opinion, that is, obtain the network space security risk points of the weapon system and the corresponding reinforcement adjustment opinions. All three participating parties can further adjust the content of the confrontation, and finally the director checks it; after the summary period ends, it switches to the ended stage, which supports system users to replay historical deductions, supports importing and exporting deduction records, and can form reusable attack knowledge information from the attack chain.
[0085] To further illustrate the present invention, in combination with the above preferred solution, another embodiment of the method for evaluating and deducing the network space security of a weapon system is provided, as Figure 3 shown, including:
[0086] S31: Abstractly model the network space of the weapon system to obtain a network space model of the weapon system;
[0087] S32: Conduct a basic static evaluation of the network security of the network space model;
[0088] S33: Determine the threat behaviors for single-point threat assessment through the threat framework, perform simulated attacks on the cyberspace model through the threat behaviors, and obtain the attack responses of the cyberspace model, so as to evaluate the defense capabilities of the cyberspace model against corresponding threat behaviors;
[0089] S34: Determine the attack sequences for attack chain threat assessment through the threat framework, perform simulated attacks on the cyberspace model through the attack sequences, and obtain the attack responses of the cyberspace model, so as to evaluate the defense capabilities of the cyberspace model against corresponding attack sequences;
[0090] S35: Combine the evaluation report, based on the threat framework and the cyberspace model, and deduce the attack and defense process of the weapon system's cyberspace through the threat deduction system;
[0091] S36: Determine the security risks of the weapon system's cyberspace according to the attack and defense deduction situation.
[0092] Figure 3 The above embodiments perform basic static assessment, single-point threat assessment, and attack chain threat assessment through a hierarchical threat assessment method, discover the exposed surfaces, vulnerabilities, and attackable points existing in the weapon system, and then through adversarial threat deduction and judgment, simulate real cyberspace attacks as much as possible to discover potential risks. The static assessment is directly performed on the data of the model instance, such as firmware model, OS version vulnerabilities, security reinforcement strategies, etc., and an automated execution method is adopted; the single-point threat assessment selects a specific threat step or behavior in the cyberspace threat framework for directional assessment and response, and a semi-automated or human-computer interaction method is adopted; the attack chain threat assessment is carried out for a specific attack sequence, and a semi-automated or human-computer interaction method is adopted, so as to discover the exposed surfaces, vulnerabilities, and attackable points existing in the weapon system. Through adversarial threat deduction and judgment in the sand table mode, real cyberspace attacks are simulated as much as possible to discover potential risks, so as to comprehensively solve the cyberspace security problems of the weapon system from a single piece of equipment to an equipment system, and effectively test and discover the vulnerable links and security vulnerabilities of the weapon system's cyberspace security. Figure 3 The above embodiments are based on Figure 1 the preferred solutions of the above embodiments, so Figure 3 the descriptions of the above embodiments are relatively simple, and for corresponding parts, please refer to Figure 1 the above embodiments.
[0093] The present invention provides an embodiment of a weapon system cyberspace security assessment and deduction device, as Figure 4 shown, including:
[0094] The cyber - space model construction module 41 is used to abstractly model the cyber - space of the weapon system to obtain the cyber - space model of the weapon system;
[0095] The threat assessment module 42 is used to conduct a basic static assessment of the network security of the cyber - space model, conduct single - point threat assessment and attack - chain threat assessment on the cyber - space model through a threat framework, summarize the assessment results, and output an assessment report;
[0096] The offense - defense deduction module 43 is used to combine the assessment report and deduce the offense - defense process of the cyber - space of the weapon system based on the threat framework and the cyber - space model to determine the security risks of the cyber - space of the weapon system.
[0097] Preferably, conducting single - point threat assessment on the cyber - space model through a threat framework specifically includes:
[0098] Determine the threat behaviors for single - point threat assessment through the threat framework, conduct simulated attacks on the cyber - space model through the threat behaviors, obtain the attack responses of the cyber - space model, and use them to evaluate the defense capabilities of the cyber - space model in response to the corresponding threat behaviors.
[0099] Preferably, conducting attack - chain threat assessment on the cyber - space model through a threat framework specifically includes:
[0100] Determine the attack sequences for attack - chain threat assessment through the threat framework, conduct simulated attacks on the cyber - space model through the attack sequences, obtain the attack responses of the cyber - space model, and use them to evaluate the defense capabilities of the cyber - space model in response to the corresponding attack sequences.
[0101] Preferably, the assessment report includes the vulnerabilities, attackable points, cyber - attack exposure surface, and recommended reinforcement measures of the cyber - space model.
[0102] Preferably, the deduction of the offense - defense process of the cyber - space of the weapon system is realized through a threat deduction system, and the threat deduction system includes:
[0103] The director - side module is used to send deduction instructions to the attacker - side module and conduct full - cycle management of the offense - defense deduction;
[0104] The attacker - side module is used to receive the deduction instructions sent by the director - side module and conduct simulated attacks on the cyber - space model according to the threat framework;
[0105] The defender - side module is used to combine the assessment report and conduct defensive responses to the specific simulated attacks executed by the attacker - side module.
[0106] Preferably, the director module is specifically configured to:
[0107] Generate an attack and defense deduction script according to a preset rule and obtain an attack and defense deduction task;
[0108] Generate a deduction instruction according to the attack and defense deduction task and send it to the attacker module;
[0109] Perform full-cycle management on each stage of the attack and defense deduction; each stage of the attack and defense deduction includes: not started stage, preparatory period stage, confrontation period stage, summary period stage, and ended stage.
[0110] Preferably, the attacker module is specifically configured to:
[0111] In the preparatory period stage, receive the deduction instruction sent by the director module, obtain the corresponding attack chain in the threat framework according to the deduction instruction, and configure attack cards for each node of the attack chain;
[0112] In the confrontation period stage, submit the attack chain to the director module and perform a simulated attack on the cyberspace model through the attack chain.
[0113] Preferably, the defender module is specifically configured to:
[0114] In the preparatory period stage, perform defense reinforcement on the cyberspace model according to the evaluation report;
[0115] In the confrontation period stage, verify the defense reinforcement situation of the specific strike position of the attack card, and match the corresponding defense strategy or perform an attack response according to the verification situation.
[0116] Preferably, the director module is further configured to:
[0117] Adjust the attack and defense deduction script and the attack and defense deduction task in the not started stage according to the change of the preset rule;
[0118] In the confrontation period stage, receive the attack chain sent by the attacker module, monitor the attack and defense deduction processes of the attacker module and the defender module according to the attack chain, and use it to judge the attack and defense deduction situation;
[0119] In the summary period stage, obtain the cyberspace security risk points of the weapon system and the corresponding reinforcement and adjustment opinions according to the monitoring situation in the confrontation period stage.
[0120] Preferably, monitoring the attack and defense deduction processes of the attacker module and the defender module according to the attack chain specifically includes:
[0121] Monitor the simulated attack situations of each attack card according to the attack chain. When a simulated attack is performed through an attack card, if the simulated attack is successful or the defense module does not respond to the attack, it is determined that there is a security risk at the specific location of the cyber space model attacked by the attack card.
[0122] The process of the device embodiment of the present invention is similar to that of the method embodiment in some parts. The description of the device embodiment is relatively simple, and the corresponding parts can be referred to the method embodiment.
[0123] The embodiment of the present invention also provides an electronic device, as Figure 5 shown, which can implement the process of the embodiment of the present invention Figure 1 、 3 shown. The electronic device includes: a housing 51, a processor 52, a memory 53, a circuit board 54, and a power supply circuit 55. Among them, the circuit board 54 is arranged inside the space surrounded by the housing 51, and the processor 52 and the memory 53 are arranged on the circuit board 54; the power supply circuit 55 is used to supply power to each circuit or device of the above electronic device; the memory 53 is used to store executable program codes; the processor 52 runs the program corresponding to the executable program code by reading the executable program code stored in the memory, and is used to execute the method described in the foregoing embodiment.
[0124] For the specific execution process of the above steps by the processor 52 and the further steps executed by the processor 52 by running the executable program code, reference can be made to the description of the embodiment shown in the present invention Figure 1 、 3 shown, which will not be elaborated here.
[0125] The embodiment of the present invention also provides a computer-readable storage medium. The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method described in the foregoing embodiment.
[0126] The present invention focuses on the evaluation of the cyberspace security capabilities of weapon systems and solves the fundamental problems restricting the cyberspace security of weapon systems. It adopts a hierarchical threat assessment method based on basic static assessment, single-point threat assessment, and attack-chain threat assessment, as well as a threat deduction method under the sand table deduction mode, comprehensively studies the cyberspace security issues of weapon systems from single equipment to equipment systems, effectively tests and discovers the vulnerable links and security loopholes in the cyberspace security of weapon systems, and then creates a security closed-loop from threat assessment to capability improvement, forming a technical support and traction mechanism for the construction of the cyberspace security capabilities of weapon systems. The present invention is fundamental and generalizable, and can be replicated and promoted in various stages of the design, research and development, application, support, and retirement of various types of weaponry in our military, improving the network security of various types of weapon systems in our military and ensuring the combat effectiveness of weapon systems. In addition, the present invention can also be widely applied to the network security assessment, design of network security protection solutions, network security reinforcement, etc. of various types of critical information infrastructure and important information systems such as energy, medical care, communication, and finance, and has broad application prospects.
[0127] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for network space security assessment and deduction of a weapon system, characterized in that, Including: Abstractly model the cyber space of the weapon system to obtain a cyber space model of the weapon system; Conduct a basic static assessment of the network security of the cyber space model, conduct single-point threat assessment and attack chain threat assessment on the cyber space model through a threat framework, summarize the assessment results, and output an assessment report; Combined with the assessment report, deduce the attack and defense process of the cyber space of the weapon system based on the threat framework and the cyber space model to determine the security risks of the cyber space of the weapon system; Among them, conducting single-point threat assessment on the cyber space model through a threat framework includes: determining threat behaviors for single-point threat assessment through the threat framework, simulating attacks on the cyber space model through the threat behaviors, obtaining attack responses of the cyber space model, and using them to evaluate the defense capabilities of the cyber space model to respond to corresponding threat behaviors; Conducting attack chain threat assessment on the cyber space model through a threat framework includes: determining an attack sequence for attack chain threat assessment through the threat framework, simulating attacks on the cyber space model through the attack sequence, obtaining attack responses of the cyber space model, and using them to evaluate the defense capabilities of the cyber space model to respond to corresponding attack sequences; Deducing the attack and defense process of the cyber space of the weapon system is realized through a threat deduction system. The threat deduction system includes: a director module for sending deduction instructions to the attacker module and conducting full-cycle management of the attack and defense deduction; an attacker module for receiving the deduction instructions sent by the director module and simulating attacks on the cyber space model according to the threat framework; a defender module for combining the assessment report and conducting defense responses to the specific simulated attacks executed by the attacker module.
2. The method according to claim 1, characterized in that, The assessment report includes the vulnerabilities, attackable points, cyber attack exposure surface, and recommended reinforcement measures of the cyber space model.
3. The method according to claim 2, characterized in that, The director module is specifically used for: Generating an attack and defense deduction script according to preset rules and obtaining an attack and defense deduction task; Generating deduction instructions according to the attack and defense deduction task and sending them to the attacker module; Conducting full-cycle management of each stage of the attack and defense deduction; each stage of the attack and defense deduction includes: an unstarted stage, a preparatory stage, a confrontation stage, a summary stage, and an ended stage.
4. The method according to claim 3, characterized in that, The attacker module is specifically used for: In the preparatory stage, receiving the deduction instructions sent by the director module, obtaining the corresponding attack chain in the threat framework according to the deduction instructions, and configuring attack cards for each node of the attack chain; In the confrontation stage, submitting the attack chain to the director module and simulating attacks on the cyber space model through the attack chain.
5. The method according to claim 4, characterized in that, The defender module is specifically used for: In the preparatory stage, conducting defense reinforcement on the cyber space model according to the assessment report; In the confrontation stage, verifying the defense reinforcement situation of the specific strike position of the attack card, and matching corresponding defense strategies or making attack responses according to the verification situation.
6. The method according to claim 5, characterized in that, The director module is also used for: Adjust the attack and defense deduction scenario and the attack and defense deduction task in the not-yet-started stage according to the changes of the preset rules; In the confrontation stage, receive the attack chain sent by the attacker module, and monitor the attack and defense deduction process of the attacker module and the defender module according to the attack chain to determine the situation of the attack and defense deduction; In the summary stage, obtain the network space security risk points of the weapon system and the corresponding reinforcement and adjustment opinions according to the monitoring situation in the confrontation stage.
7. The method according to claim 6, characterized in that, Monitoring the attack and defense deduction process of the attacker module and the defender module according to the attack chain specifically includes: Monitoring the simulated attack situation of each attack card according to the attack chain. When a simulated attack is carried out through an attack card, if the simulated attack is successful or the defender module does not make an attack response, it is determined that there is a security risk at the specific position of the cyber space model attacked by the attack card.
8. A device for network space security assessment and deduction of a weapon system, characterized in that, Including: A cyber space model construction module for abstractly modeling the cyber space of the weapon system to obtain a cyber space model of the weapon system; A threat assessment module for performing a basic static assessment of the network security of the cyber space model, performing single-point threat assessment and attack chain threat assessment on the cyber space model through a threat framework, summarizing the assessment results, and outputting an assessment report; An attack and defense deduction module for deducing the attack and defense process of the cyber space of the weapon system based on the threat framework and the cyber space model in combination with the assessment report to determine the security risks of the cyber space of the weapon system; Among them, performing single-point threat assessment on the cyber space model through the threat framework includes: determining the threat behavior for single-point threat assessment through the threat framework, performing a simulated attack on the cyber space model through the threat behavior, and obtaining the attack response of the cyber space model to evaluate the defense ability of the cyber space model to respond to the corresponding threat behavior; Performing attack chain threat assessment on the cyber space model through the threat framework includes: determining the attack sequence for attack chain threat assessment through the threat framework, performing a simulated attack on the cyber space model through the attack sequence, and obtaining the attack response of the cyber space model to evaluate the defense ability of the cyber space model to respond to the corresponding attack sequence; Deducing the attack and defense process of the cyber space of the weapon system is realized through a threat deduction system. The threat deduction system includes: a director module for sending deduction instructions to the attacker module and performing full-cycle management of the attack and defense deduction; an attacker module for receiving the deduction instructions sent by the director module and performing a simulated attack on the cyber space model according to the threat framework; a defender module for combining the assessment report and performing a defensive response to the specific simulated attack executed by the attacker module.
9. An electronic device, characterized in that,The electronic device includes: a housing, a processor, a memory, a circuit board, and a power supply circuit. Among them, the circuit board is disposed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to each circuit or device of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, and is used to execute the method described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method described in any one of claims 1-7.
Citation Information
Patent Citations
Network environment current situation evaluation method and device, electronic equipment and storage medium
CN111030837A
Simulation modeling method and device for network attack and defense process and network turn war chess
CN113536573A