A semi-automated security testing method based on the PDCA cycle

Through the semi-automated security testing method based on PDCA cycle, the tool sequence is optimized by packaging modeling, knowledge graphs and ant colony algorithm, the problems of tool selection randomness and resource waste in the existing technology are solved, and efficient and intelligent security testing is achieved.

CN115061910BActive Publication Date: 2025-07-04BEIJING INST OF COMP TECH & APPL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210677006.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-15
Publication Date
2025-07-04
Estimated Expiration
2042-06-15

AI Technical Summary

Technical Problem

When facing a diverse test object, existing security testing technology relies on manual experience in the selection of tooling, and resource scheduling is very random, resulting in inefficient testing and making it difficult to achieve comprehensive and efficient security detection.

Method used

The semi-automated security testing method based on PDCA cycle is adopted, and through packaging modeling, knowledge graph construction, attack graph generation and ant colony algorithm optimization, the independent planning and driving execution of test tools are realized, the tool difference is blocked, and the degree of automation is improved.

Benefits of technology

It improves the independent selection and call capability of testing tools, enhances the intelligence and efficiency of security testing, can adapt to the detection needs of diverse test objects, and reduces resource waste and manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115061910B_ABST
    Figure CN115061910B_ABST
Patent Text Reader

Abstract

The present invention relates to a semi-automatic security testing method based on the PDCA cycle, and belongs to the field of network security technology. The present invention focuses on the "plan-design-check-correct" cycle of PDCA, designs a semi-automatic cycle iterative upgrade security testing method of "action planning, on-demand compilation, optimized scheduling, and execution feedback", realizes efficient security testing for test objects, shields the differences of test tools in input and output, execution interaction, etc., and forms the ability to autonomously plan and drive execution of test tasks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a semi - automated security testing method based on the PDCA cycle. Background Technique

[0002] The rapid development and extensive application of information network technology have greatly promoted the digitalization, networking, and modernization processes of China's critical information infrastructure. The research and deployment of information systems at different levels and of different types, such as office systems, information networks, and infrastructure, have realized the informatization of various important industries and fields in China, such as energy, communication, transportation, and public security. These systems are interconnected through the network to form a systematic and networked information system, promoting the continuous improvement of China's informatization and digitalization capabilities and contributing to accelerating the construction of Digital China and implementing the network power strategy.

[0003] However, with the development of network technology, the threats of network security attacks are increasing day by day. According to the "Analysis of the Semi - annual Network Security Situation in 2021" report released by the Security Center of the Ministry of Industry and Information Technology, the current network security situation is severe. The number of global network attack events has increased significantly, and large - scale data leakage events have emerged continuously, posing great security risks to critical information infrastructure. With the development of the digital era and the deepening of the Internet of Everything, lawbreakers have also accelerated their transfer to the online world, presenting a professional, large - scale, and industrialized network attack situation, and the network security protection situation of information systems is becoming increasingly severe. Globally, major countries in the world regard network security as a strategic focus of national security, have successively introduced various comprehensive network security policies, and formulated requirements for strengthening information security, data security, and supply chain security, etc., putting forward enforceable requirements for the network security capabilities of various industries.

[0004] To ensure the continuous safe and stable operation of China's increasingly developed information systems and critical infrastructure, it is necessary to continuously carry out scientific security testing activities on critical information infrastructure, fully discover various security defects existing in the system, scientifically evaluate the security defense capabilities of the system, and provide support for eliminating the security defects existing in the system to ensure the safe and stable operation of China's critical information infrastructure.

[0005] The core idea of security testing is to verify the relative security level of the system and increase the cost of breaking into the system. From the perspective of initiative, security testing can be divided into active defense inspection and penetration testing, and penetration testing includes rule - based security scanning and manual penetration testing. Security testing relies on personnel experience and test tool support, continuously deeply explores and exploits the vulnerabilities of the target system, and realizes the comprehensive testing of the target.

[0006] To improve the scientificity, sufficiency, and efficiency of security testing, researching methods to improve the degree of automation of security testing has extremely important functions and significance:

[0007] First, it can improve the intelligence level of security testing, realize the autonomous selection, invocation, and driving of tool resources, reduce the dependence on personnel, improve the security detection efficiency, and form a rapid and effective detection ability for computer and network information systems.

[0008] Second, effective security testing technologies can, through the efficient planning and driving execution of tools, shield the differences between tools, avoid the adverse impact of the doubling of test execution costs caused by the growth of the types of security testing tools with the expansion of the scope of test target objects, support the growing scope of detection objects, and improve the detection ability of security testing.

[0009] To address the deficiency that current penetration testing tools are only applicable to traditional computer networks and expand the detection scope for target objects such as big data platforms, cloud platforms, video surveillance devices, and office automation devices, it is necessary to improve the detection ability of the penetration testing platform, add new technologies and new means to meet the continuously evolving needs of detection objects.

[0010] Traditional security testing technologies have the following four main limitations in the planning and selection methods of testing tools, which affect the efficiency of security testing and restrict the development of security testing work. First, the current selection of testing tools mostly adopts a pre-allocated static resource scheduling method, and the selection of resources highly depends on the experience of testers. Second, due to the uncertainty of the execution results of test objects, dynamic adjustments are required at all stages of the test process. The current selection methods mostly rely on multiple attempts and frequent trial-and-error of testing tools, increasing resource overhead. Third, the randomness in determining test resources and paths leads to one-sidedness in testing work, and the testing process is not systematic, making it difficult to meet the comprehensive requirements of security testing. Fourth, the massive security testing resources are limited by the huge differences in aspects such as resource form, usage method, target object type, running location, execution control method, and data interface, posing high requirements on the experience of testers and increasing the difficulty of optimizing the selection of testing resources. Summary of the Invention

[0011] (1) Technical Problems to be Solved

[0012] The technical problem to be solved by the present invention is: how to design a semi-automated security testing method to achieve efficient security testing for test objects, shield the differences in input / output, execution interaction, etc. of testing tools, and form the ability of autonomous planning and driving execution of test tasks.

[0013] (2) Technical Solutions

[0014] In order to solve the above technical problems, the present invention provides a semi-automatic safety testing method based on the PDCA cycle, comprising the following steps:

[0015] Step 1: Plan: Encapsulate and model the security testing tools, plan the matching correlation between test requirements, test behaviors and test tools, and thus build a security testing knowledge graph;

[0016] Step 2: Design: Based on the results of step 1, the test path is initially compiled and constructed based on the attack graph dynamic generation method of the attack pattern, and each test node on the test path is connected to the test tool;

[0017] Step 3: Check: Use the ant colony optimization algorithm to optimize the test path set planned in step 2 and select the optimal test tool sequence;

[0018] Step 4: Correction: Based on the actual status changes during the test, feedback is given to adjust resource scheduling and path screening parameters, and the test tool sequence is continuously optimized.

[0019] Preferably, step 1 is as follows:

[0020] Step 1.1: Model and encapsulate the test tools to form a test resource pool, which is the basis for unified resource configuration, driving, and automated execution;

[0021] Firstly, we conduct multi-dimensional attribute analysis on the test tool, label the attributes from the dimensions of physical domain, logical domain and state domain, and obtain the attribute description model of the test tool;

[0022] Among them, the physical domain includes basic attributes, interface attributes, action conditions, action distance, and parameter configuration attributes: basic attributes describe the name, type, version model, and form of the tool resource; interface attributes include the interface name, interface type, transmission data type, and data format that the tool resource can provide; action conditions include the attribute information of the tool resource's operating system platform, operating support software, and dependency weaknesses; action distance includes the deployment location and connection method when the tool acts on the target object; parameter configuration attributes include the resource's parameter configuration and policy configuration information;

[0023] The logical domain includes the attributes of function, performance, effect, and trace: the function attribute describes the attack test behavior attribute characteristics that the tool can complete; the performance attribute describes the degree, efficiency, and accuracy of the tool when completing a function; the effect refers to the effect achieved by the tool on the target object; the trace value is the trace generated when the tool performs a function on the target object;

[0024] The status field contains attributes such as idle state, in-use state, fault state, reserved state, and test time: The idle state describes that the tool is currently available; the fault state describes that the tool is currently in a faulty state and cannot be called; the in-use state indicates that the tool is currently being used; the reserved state describes that the tool has been reserved for future use; the test time describes the time required for the tool to complete the current task;

[0025] Based on the test tool attribute description model, a four-element description model of {object, attribute, relationship, state} is constructed to shield the differences of test resources;

[0026] Furthermore, for the unified management and control of test tools, an interface-based encapsulation design is carried out for test tools, uniformly restricting the tool interaction interface, management and control interface, engine drive interface, and data acquisition interface, and realizing the model-based definition of test resource drive, execution, and interaction. The tool interaction interface is used to implement the input and output interaction function between the running of test tools; the management and control interface is used to implement the management and control function between the test tool and the execution platform; the engine drive interface is used to implement the execution control of the test tool; the data acquisition interface is used to collect data such as result data and tool execution status during the execution of the test tool;

[0027] Step 1.2: Extract knowledge from the basic links of security testing and establish a security testing knowledge graph;

[0028] Based on the attribute modeling of the security testing tool in Step 1.1, analyze and summarize the security testing requirements, operation behaviors, and tool attributes, extract the association rules between test requirements and test behaviors, and between test behaviors and test tools, and further construct a multi-dimensional mapping matrix between test requirements, test behaviors, and test tools. Through heterogeneous specification, a security testing knowledge graph is formed.

[0029] Preferably, in Step 1, the process of establishing the security testing knowledge graph is as follows: The construction process of the knowledge graph starts from the raw data in the three dimensions of test requirements, test behaviors, and test tools, extracts the knowledge elements from the raw data, and stores them in the data layer and schema layer of the knowledge base. On this basis, iterative construction is carried out, and the construction of the knowledge graph is completed through continuous iteration of the three stages of information extraction, knowledge fusion, and knowledge processing.

[0030] Preferably, in Step 1, based on the semantic search function of the knowledge graph, security testing knowledge queries are performed on the knowledge graph, keywords such as security testing tools and test effects are parsed and inferred, and then mapped to one or a group of concepts in the knowledge graph. Then, according to the concept hierarchy in the knowledge graph, a knowledge network centered on the query entity is returned to assist in completing test plan design and task planning.

[0031] Preferably, step 2 is specifically:

[0032] Step 2.1: Build a test pattern model;

[0033] Use five-tuple<Name,VulnerabilitySet,Pre,Effect,QuantifiedSet> To describe the test mode, Name is the name of the test mode; VulnerabilitySet is the set of vulnerabilities that the test mode exploits; Pre is the prerequisite of the test mode; Effect is the attack effect of the test mode; QuantifiedSet is the set of extended quantitative attributes of the test mode. According to the nature of the test, the relationship between the various exploit prerequisites and the various exploit consequences of the test mode can only contain an "and" relationship, not an "or" relationship;

[0034] Step 2.2: Build an attack graph based on step 2.1

[0035] The process of constructing an attack graph is to match the tools according to the target network attack surface and weaknesses, and the test mode, so that the test mode can be instantiated into atomic test actions, and the premise and effect connection between two adjacent test atoms on the test path is used to extend the test path forward, completing the construction of the test path sequence and the attack graph;

[0036] Step 2.3: Plan the test path based on the attack graph

[0037] Based on the attack graph constructed in step 2.2, the path traversal algorithm of the directed graph is used to calculate the path corresponding to the attack graph, which is the set of test paths. The attack graph is used to analyze the exposure and vulnerability of the test object, match test resources, and connect test premises and effects to form a test path plan. Under the guidance of the knowledge graph constructed in step 1, all test paths are fully traversed to ensure a comprehensive combing of the test tool sequence. The success probability of each tool sequence is calculated according to the guidance of the knowledge graph in step 1 as the input for optimization and adjustment in step 3.

[0038] Preferably, in step 2.2, the meaning of the vertices of the attack graph is expanded to include test tools and test effects, and the meaning of the edges of the attack graph is expanded to include the possibility of successful test execution, test execution time or test efficiency.

[0039] Preferably, step 3 is specifically:

[0040] Step 3.1: Assume there are y test nodes on the test tool sequence, and x optional test tools are available for allocation. The problem of solving the optimal allocation method is abstracted as learning from the ant colony algorithm to solve the problem of x ants placed on y vertices for optimal path selection. The test tool sequence is represented as: T = {T1, T2, T3, …, T x}, T i represents the i-th test tool, and the test node set is: V = {V1, V2, V3, …, V y}, V j represents the j-th test node;

[0041] Executing a test tool on a test node, the mapping relationship between the test tool and the test node resources is replaced by the following matrix:

[0042]

[0043] In the matrix, r ij represents allocating the test tool T i to the test node V j for execution;

[0044] The selection of the test tool first needs to determine a reasonable allocation relationship between the test tool and the test node. The time taken to select the test tool and the load balance of the test node are indicators to measure whether the test tool is reasonable and whether the tool chain is effective. The total execution time of a test tool sequence is: where e ij = Length i / Mips j represents the execution time of the test tool T i on the test node resource V j ;

[0045] The following improvements are made to the pheromone concentration update formula of the ant colony algorithm: The local pheromone update formula is improved to Δτ ij (t) = D / time ij , and the global pheromone update formula is improved to Δτ ij '(t) = D / besttime ij , where D is a constant, time ij represents the completion time of the test node V j executing the test tool T i , and besttime ij represents the shortest completion time of the test node V j executing the test tool T i ;

[0046] Based on the improved ant colony algorithm, in each test tool selection stage, it is dynamically adjusted according to the situation, a better tool is selected, and the results are recorded. If a test tool sequence can complete the test work, the test tool sequence is recorded. If it is unsuccessful, it is not recorded, and the original path is returned to the source point in the reverse direction to destroy this path. Based on the improved pheromone Δτ ij (t) Update the pheromone. The ants start from the source again and continue to search for and construct the test tool sequence. After constructing an optimal test tool sequence, they record it and continue to call the improved ant colony algorithm to construct the test tool sequence. When the same test tool sequence appears, they go back in reverse order and contaminate the test tool selection at the last step of the sequence, thereby constructing the optimal test tool chain of the remaining solution space and achieving full coverage of the test path.

[0047] Step 3.2: Perform load balancing selection of test tools through weighted round-robin method;

[0048] The execution status of the test tool is understood as performance. The selection of the test tool can be understood as selecting the test tool with the best performance from the set of test tool types to be selected. The test tool is assigned permissions, including two load balancing weights, weight and effective_weight. Weight is the initial weight of the test tool, which remains unchanged after assignment. The initial weight is assigned according to the execution time e of the test tool calculated in step 3.1. ij , the prerequisite Pre of the test mode defined in step 2.1 is comprehensively evaluated, effective_weight is the effective weight of the test tool, and its initial value is weight. After the test tool is selected and called to be in use, the effective weight of the test tool will be reduced. If the test tool is in a faulty state, the effective weight will also be reduced. After that, when the test tool is released or the fault is rectified, the effective weight will gradually increase until it is restored to weight; the tool load balancing selection method is to select the test tool with the highest value from the test tool set according to the effective_weight value, which is the test tool selection result for the current corresponding test node.

[0049] Preferably, step 4 is to dynamically optimize and adjust the feedback of the test effect and the test path according to the dynamic changes of the test information during the test process, and use the adjustment results to dynamically update the test requirements of step 1, the matching correlation between the test behavior and the test tool, the attack graph of step 2, the pheromone concentrations of the two ant colony algorithms in step 3, and the load balancing weight in step 3. These parameters form a feedback mechanism to improve the calculation methods of steps 1 to 3, and optimize, adjust and improve the planning scheme of the next test tool.

[0050] The invention also provides a system for implementing the method.

[0051] The invention also provides an application of the method in the technical field of network security.

[0052] (III) Beneficial effects

[0053] Compared with the prior art, the present invention has the following advantages:

[0054] (1) With the expansion of test target types, the types and number of test tools have increased exponentially. Different tools have great differences in the driving execution process. The present invention encapsulates and models the tools, uniformly describes the tool attributes, shields the differences between the tools, and improves the tools' autonomous selection and call execution capabilities.

[0055] (2) Through the use of technologies such as attack graphs and ant colony algorithms, intelligent genes are injected into the execution process of the tool. Compared with the current tool selection and execution methods that mainly rely on static selection and manual attempts, it has stronger efficiency and improves the degree of automation of security testing. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 A flow chart of the safety testing method based on the PDCA cycle designed for the present invention;

[0057] Figure 2 This is the test tool attribute description model involved in the present invention. DETAILED DESCRIPTION

[0058] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below in conjunction with the drawings and examples.

[0059] The present invention proposes a semi-automatic security testing method based on the PDCA cycle. Focusing on the "plan-design-check-correct" cycle of PDCA, a semi-automatic cyclic iterative upgrade security testing method of "action planning, on-demand compilation, optimized scheduling, and execution feedback" is designed to achieve efficient security testing for test objects, shield the differences of test tools in input and output, execution interaction, etc., and form the ability to autonomously plan and drive execution of test tasks.

[0060] Security testing is conducted by testers who study the vulnerabilities of the information system being tested, select a series of reasonable tools, and construct a security testing tool sequence through orderly combination, and implement specific testing requirements through the execution of the tools. The selection of test tools has a certain matching, that is, the tool's capability requirements match the test requirements and the vulnerability of the test target; the test tools have a certain correlation and dependency in calling and executing, that is, the operation of the subsequent tools in the tool execution sequence depends to a certain extent on the execution results of the previous tools. Improving the matching of tools and demand planning in security testing, as well as the degree of automation of the tool execution sequence, is the key to improving the accuracy and efficiency of security testing.

[0061] To achieve the above-mentioned purpose, the technical solution adopted by the present invention draws on the PDCA cycle concept and abstracts the security testing process into four stages. It formulates an action plan by matching related testing tools with testing requirements, preliminarily compiles the test tool sequence on demand, optimizes scheduling and selects the optimal sequence set, monitors the testing process and tool execution status feedback, and continuously optimizes tool matching and sequence construction automation through spiral iterative design to improve security testing efficiency.

[0062] Further, refer to Figure 1 The present invention designs a semi-automatic safety testing method based on the PDCA cycle, the core of which is to semi-automatically construct a test tool sequence, which specifically includes the following steps:

[0063] Step 1: Plan: Encapsulate and model the security testing tools, plan the matching correlation between test requirements, test behaviors and test tools (pairwise), and thus build a security testing knowledge graph.

[0064] This step corresponds to the P-Plan stage of the PDCA cycle, which aims to clarify the test objectives and establish the final state of achieving the test requirements. The details are as follows:

[0065] Step 1.1: Model and encapsulate the test tools to form a test resource pool, which serves as the basis for unified resource configuration, drive, and automated execution.

[0066] The core of test tool modeling is the attributes of the test tool. First, we conduct a multi-dimensional attribute analysis on the test tool and label the attributes from the dimensions of physical domain, logical domain, state domain, etc. Figure 2 The test harness properties shown describe the model.

[0067] Among them, the physical domain includes attributes such as basic attributes, interface attributes, operating conditions, operating distance, parameter configuration, etc.: Basic attributes describe the basic attributes of tool resources, such as name, type, version model, form, etc.; Interface attributes mainly refer to information such as the interface name, interface type, transmitted data type, data format, etc. that the tool resource can provide; Operating conditions mainly refer to the attribute information of elements such as the operating system platform, operating support software, and dependent vulnerabilities of the tool resource; Operating distance mainly refers to the deployment location and connection method when the tool acts on the target object, such as remote, close, wired, wireless, etc.; Parameter configuration attributes mainly refer to information such as the parameter configuration and policy configuration of the resource.

[0068] The logical domain includes attributes such as function, performance, effect, trace, etc.: Function attributes describe the attribute characteristics of attack and test behaviors that the tool can complete and implement, such as port scanning, sniffing, etc.; Performance attributes describe characteristics such as the degree, efficiency, and accuracy when the tool completes a certain function; The acting effect refers to the effect achieved when the tool acts on the target object, such as service denial, system error, password stealing, etc.; Acting trace values refer to the traces generated when the tool performs a certain function on the target object, such as logs, traffic records, IDS records, etc.

[0069] The status domain includes attributes such as idle state, in-use state, fault state, reserved state, test time, etc.: The idle state describes that the tool is currently in an available state; The fault state describes that the current state of the tool is faulty and cannot be called; The in-use state indicates that the tool is currently being used; The reserved state describes that the tool has been reserved for future use at a certain moment; The test time describes the time required for the tool to complete the current task.

[0070] Based on the described test tool attribute description model, a four-element description model of {object, attribute, relationship, state} is constructed to shield the differences of test resources.

[0071] Furthermore, for the unified management and control of test tools, an interface-based encapsulation design is carried out for test tools, uniformly restricting tool interaction interfaces, management and control interfaces, engine drive interfaces, data acquisition interfaces, etc., to achieve a model-based definition of test resource drive, execution, and interaction. The tool interaction interface is used to implement the input-output interaction function during the operation of test tools; The management and control interface is used to implement the management and control functions between the test tool and the execution platform, including configuration management, status reporting, etc.; The engine drive interface is used to implement the execution control of test tools, including instruction execution, tool startup and shutdown, etc.; The data acquisition interface is used to implement the acquisition of result data, tool execution status and other data during the execution process of test tools.

[0072] Step 1.2: Extract knowledge from the basic links of security testing and establish a security testing knowledge graph.

[0073] Based on step 1.1, the attributes of the security testing tool are modeled, and the security testing requirements, operational behaviors, and tool attributes are analyzed and summarized. Combined with the experience of security testing experts, the association rules between test requirements and test behaviors, and between test behaviors and test tools are extracted. A multidimensional mapping matrix between requirements, behaviors, and tools is further constructed. Through heterogeneous specifications, a security testing knowledge graph is formed, laying a "planning" foundation for the automatic construction of a security testing tool sequence.

[0074] The following is a brief description of the process of establishing a security testing knowledge graph in the present invention. The process of constructing a knowledge graph starts from the original data of three dimensions, namely, test requirements, test behaviors, and test tools, extracts knowledge elements from the original data, and stores them in the data layer and model layer of the knowledge base. On this basis, iterative construction is carried out, and the construction of the knowledge graph is completed through continuous iteration of the three stages of information extraction, knowledge fusion, and knowledge processing.

[0075] Based on the semantic search function of the knowledge graph, security testing knowledge queries are performed on the knowledge graph, and keywords such as security testing tools and test effects are parsed and inferred, and then mapped to one or a group of concepts in the knowledge graph. Then, based on the conceptual hierarchy in the knowledge graph, a knowledge network centered on the query entity is returned to assist in completing test plan design and task planning.

[0076] The rationality of test tool selection is comprehensively measured by integrating factors such as the matching of test tools with test requirements, test tool completion time and efficiency, and test tool load balancing. The following uses step 2 to solve the problem of matching test tools with test requirements, and step 3 to solve the problems of test tool time, efficiency, and load balancing.

[0077] Step 2: Design: Based on the results of step 1, the attack graph dynamic generation method based on the attack pattern is used to preliminarily compile and construct the test path, and each test node on the test path is connected to the test tool.

[0078] This step corresponds to the D-Do phase of the PDCA cycle, which aims to perform preliminary planning and complete the matching of test tools and test requirements.

[0079] Step 2.1: Construct a test pattern model. The test pattern is described by a five-tuple <Name, VulnerabilitySet, Pre, Effect, QuantifiedSet>, where Name is the name of the test pattern; VulnerabilitySet is the set of vulnerabilities exploited by this test pattern; Pre is the precondition of this test pattern; Effect is the attack effect of this test pattern; and QuantifiedSet is the set of extended quantification attributes of the test pattern. According to the test nature, there can only be an "AND" relationship between the preconditions and between the consequences of each exploitation of the test pattern, and there cannot be an "OR" relationship.

[0080] Step 2.2: Construct an attack graph based on Step 2.1.

[0081] The test pattern is the precondition for constructing the attack graph. The process of constructing the attack graph mainly matches the tool according to the target network attack surface and vulnerabilities, instantiates the test pattern into atomic test actions, and uses the connection between the preconditions and effects of two adjacent test atoms on the test path to extend the test path forward, completing the construction of the test path sequence and the attack graph.

[0082] The present invention makes an improved analysis based on the existing directed attack graph. In the concept of the current attack graph, the vertices represent network security elements such as target hosts, services, vulnerabilities, permissions, etc., and can also represent states such as nodes being cracked and permissions being obtained, while the edges represent attack action behaviors. On this basis, combining the connotation of the knowledge graph constructed in Step 1, the meaning of the vertices is extended to add content such as test tools and test effects, and the meaning of the edges is added with content such as the possibility of successful test execution, test execution time, or test efficiency.

[0083] Step 2.3: Perform test path planning based on the attack graph. Based on the attack graph constructed in Step 2.2, use the path traversal algorithm of the directed graph to calculate the paths corresponding to the attack graph, which is the set of test paths. Use the construction of the attack graph to analyze the exposure surface and vulnerabilities of the test object, match test resources, connect test preconditions and effects, etc. to form a test path plan, and under the guidance of the knowledge graph constructed in Step 1, fully traverse all test paths to ensure a comprehensive sorting of the test tool sequence. Calculate the success probability for each tool sequence according to the guidance of the knowledge graph in Step 1 as the input for subsequent step optimization and adjustment.

[0084] Step 3: Inspection: Use the ant colony optimization algorithm to optimize the set of test paths planned in Step 2 and screen and schedule the optimal test tool sequence.

[0085] This step corresponds to the C-Check phase of the PDCA cycle, aiming to observe the situation during the execution process and optimize the screening and testing tool sequence towards the optimal direction.

[0086] Step 3.1: Introduce the concept of ant colony algorithm to optimize the scheduling of the execution efficiency of the testing tool sequence. Introducing the ant colony algorithm can help solve complex optimization problems and also support combinatorial problems. In this invention, the ant colony algorithm is applied to the selection of the testing tool sequence during the security testing process, and the globally optimal testing tool sequence is screened from the set of testing paths planned in Step 2.

[0087] Assume that there are y testing nodes on the testing tool sequence and x optional testing tools for allocation. The problem of solving the optimal allocation method can be abstracted as referring to the ant colony algorithm to solve the problem of x ants placed on y vertices for optimal path selection. Under the guidance of this idea, the testing tool sequence (set) is represented as: T = {T1, T2, T3, …, T x}, T i represents the i-th testing tool, and the set of testing nodes is: V = {V1, V2, V3, …, V y}, V j represents the j-th testing node.

[0088] When executing a testing tool on a testing node, the mapping relationship between the testing tool and the testing node resources is replaced by the following matrix:

[0089]

[0090] In the matrix, r ij represents allocating the testing tool T i to the testing node V j for execution.

[0091] The selection of the testing tool first needs to determine a reasonable allocation relationship between the testing tool and the testing node. The time taken to select the testing tool to complete and the load balancing degree of the testing node are important indicators to measure whether the testing tool is reasonable and whether the tool chain is effective. The total execution time of a testing tool sequence is: where e ij = Length i / Mips j represents the execution time (when the testing tool T i is on the testing node resource V j ).

[0092] To improve the efficiency of selecting the testing tool for execution, the pheromone concentration update formula of the ant colony algorithm is improved. The local pheromone update formula is improved to Δτ ij (t) = D / time ij, and the global pheromone update formula is Δτ ij '(t) = D / besttime ij . Where D is a constant, and time ij represents the completion time when the test node V j executes the test tool T i , and besttime ij represents the shortest completion time when the test node V j executes the test tool T i .

[0093] Introduce and improve the ant colony algorithm, which can be dynamically adjusted according to the situation at each test tool selection stage, select a better tool, and record the results. If a test tool sequence can complete the test work, the test tool sequence will be recorded; if not, it will not be recorded. Then, return along the original path to the source point in reverse (with memory function), destroy this path, and update the pheromone based on the improved pheromone Δτ ij (t). The ants start from the source point again and continue to search for constructing a test tool sequence. After constructing an optimal test tool sequence, record it, and continue to call the improved ant colony algorithm to construct a test tool sequence. When the same test tool sequence appears, reverse and roll back, and contaminate the selection of the last step of the sequence, so as to construct the optimal test tool chain in the remaining solution space and achieve full coverage of the test path.

[0094] Step 3.2: The actual meaning of each test tool selection in the planned test tool execution sequence is the type of the test tool. For the planned test tool execution sequence, when calling the test tool, it is possible that the test tool is in the fault state or in-use state defined in Step 1 and cannot be called immediately. Therefore, factors such as the type, quantity, and state of the test tool need to be considered overall.

[0095] In this step, the load balancing selection of the test tool is performed by the weighted round-robin method. Understand the test tool execution status as performance, and the selection of the test tool can be understood as selecting the test tool with the best performance from the set of test tool types to be selected. Assign permissions to the test tool, including two load balancing weights, weight and effective_weight. Among them, weight is the initial weight of the test tool, which remains fixed after assignment. The assignment of the initial weight is based on the execution time e of the test tool calculated in Step 3.1 ijComprehensively evaluate the preconditions (prerequisites for test tool execution) of the test mode defined in Step 2.1, such as Pre, and give it through expert knowledge. effective_weight is the effective weight of the test tool, and the initial value is weight. After the test tool is selected and in the in-use state, the effective weight of the test tool will be reduced. If the test tool is in the fault state, the effective weight will also be reduced. After that, when the test tool is released or the fault is resolved, the effective weight will gradually increase until it returns to weight. The purpose of this is to reduce the weight of the unavailable state of the test tool. The tool load balancing selection method is to select the test tool with the highest value from the test tool set according to the effective_weight value, which is the test tool selection result corresponding to the current test node.

[0096] Step 4: Correction: Combine the actual state changes during the test process, feedback the adjustment of resource scheduling and path screening parameters, and continuously optimize the test tool sequence.

[0097] This step corresponds to the A - Action stage of the PDCA cycle, aiming to dynamically correct and adjust the parameter changes of the tool sequence planning and execution according to the execution results, continuously optimize the test process, and ultimately achieve the improvement of the semi-automation ability of the test process.

[0098] Integrate the experience and knowledge of testers. According to the dynamic changes of test information during the test process, dynamically optimize and adjust the feedback of test effects and test paths, and use the adjustment results to dynamically update parameters such as the matching correlation between test requirements, test behaviors and test tools in Step 1, the (tool allocation) attack graph in Step 2, the pheromone concentration of the two ant colony algorithms in Step 3, and the load balancing weight in Step 3, etc., to form a feedback mechanism to improve the operation methods of Steps 1 - 3 and optimize and improve the planning scheme of the next test tool.

[0099] The above is only the preferred implementation manner of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the technical principle of the present invention, several improvements and deformations can still be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.

Claims

1. A semi - automated security testing method based on the PDCA cycle, characterized in that, The following steps are involved: Step 1: Plan: Encapsulate and model security testing tools, plan the matching correlation between test requirements, test behaviors and test tools, and thus build a security testing knowledge graph; Step 2: Design: Based on the results of step 1, the test path is initially compiled and constructed based on the attack graph dynamic generation method of the attack pattern, and each test node on the test path is connected to the test tool; Step 3: Check: Use the ant colony optimization algorithm to optimize the test path set planned in step 2 and select the optimal test tool sequence; Step 4: Correction: Combined with the actual state changes during the test, feedback is given on the adjustment of resource scheduling and path screening parameters, and the test tool sequence is continuously optimized; Step 1 includes: Step 1.1: Model and encapsulate the test tools to form a test resource pool, which is the basis for unified resource configuration, driving, and automated execution; Firstly, we conduct multi-dimensional attribute analysis on the test tool, label the attributes from the dimensions of physical domain, logical domain and state domain, and obtain the attribute description model of the test tool; The physical domain includes basic attributes, interface attributes, action conditions, action distance, and parameter configuration; the logical domain includes functions, performance, effects, and traces; the state domain includes idle state, in-use state, fault state, reservation state, and test time. Based on the test tool attribute description model, a four-element description model of {object, attribute, relationship, state} is constructed to shield the differences of test resources; Furthermore, in order to achieve unified management and control of test tools, the test tools are designed with interface packaging, and the tool interaction interface, management and control interface, engine drive interface, and data collection interface are uniformly constrained to achieve modeling definition of test resource drive, execution, and interaction. The tool interaction interface is used to realize the input and output interaction functions between the running of test tools; the management and control interface is used to realize the management and control functions between the test tools and the execution platform; the engine drive interface is used to realize the execution control of the test tools; the data collection interface is used to realize the collection of result data and tool execution status during the execution of the test tools.

2. The method according to claim 1, wherein In step 1.1: Basic attributes describe the name, type, version model, and form of tool resources; interface attributes include information such as the interface name, interface type, transmission data type, and data format that tool resources can provide; action conditions include attribute information such as the operating system platform, operating support software, and dependency weaknesses of tool resources; action distance includes the deployment location and connection method when the tool acts on the target object; parameter configuration attributes include information such as resource parameter configuration and policy configuration; Functional attributes describe the attack test behavior attributes that the tool can complete and implement; performance attributes describe the degree, efficiency, and accuracy of the tool when completing a function; The effect refers to the effect achieved by the tool on the target object; the trace value refers to the trace produced when the tool performs a function on the target object; The idle state describes that the tool is currently in an available state; the fault state describes that the tool is currently in a faulty state and cannot be called; the in-use state indicates that the tool is currently being used; the reservation state describes that the tool has been reserved for future use; the test time describes the time required for the tool to complete the current task; Step 1 also includes: Step 1.2: Extract knowledge from the basic links of security testing and establish a security testing knowledge graph; Based on the attribute modeling of the security testing tool in Step 1.1, analyze and summarize the security testing requirements, operation behaviors, and tool attributes, extract the association rules between test requirements and test behaviors, and between test behaviors and test tools, and further construct a multi-dimensional mapping matrix between test requirements, test behaviors, and test tools. Through heterogeneous specification, form a security testing knowledge graph.

3. The method according to claim 2, characterized in that, In Step 1, the process of establishing a security testing knowledge graph is as follows: The construction process of the knowledge graph starts from the raw data in the three dimensions of test requirements, test behaviors, and test tools, extracts the elements of knowledge from the raw data, and stores them in the data layer and schema layer of the knowledge base. On this basis, iterative construction is carried out, and the construction of the knowledge graph is completed through continuous iteration of the three stages of information extraction, knowledge fusion, and knowledge processing.

4. The method according to claim 3, wherein In Step 1, based on the semantic search function of the knowledge graph, perform security testing knowledge queries on the knowledge graph, parse and reason about keywords such as security testing tools and test effects, and then map them to one or a group of concepts in the knowledge graph. Then, according to the concept hierarchy in the knowledge graph, return a knowledge network centered on the query entity to assist in completing test plan design and task planning.

5. The method according to claim 2, characterized in that Step 2 is specifically as follows: Step 2.1: Construct a test mode model; Describe the test mode with a five-tuple <Name, VulnerabilitySet, Pre, Effect, QuantifiedSet>, where Name is the test mode name; VulnerabilitySet is the set of vulnerabilities exploited by this test mode; Pre is the precondition of this test mode; Effect is the attack effect of this test mode; QuantifiedSet is the set of extended quantification attributes of the test mode. According to the test nature, there can only be an "and" relationship between the preconditions and between the consequences of each exploitation of the test mode, and there cannot be an "or" relationship. Step 2.2: Construct an attack graph based on Step 2.1 The process of constructing an attack graph is to match the tool according to the test mode based on the target network attack surface and vulnerabilities, so that the test mode can be instantiated into atomic test actions, and use the connection between the precondition and the effect between two adjacent test atoms on the test path to extend the test path forward and complete the construction of the test path sequence and the attack graph; Step 2.3: Perform test path planning based on the attack graph Based on the attack graph constructed in step 2.2, the path traversal algorithm of the directed graph is used to calculate the path corresponding to the attack graph, which is the set of test paths. The attack graph is used to analyze the exposure and vulnerability of the test object, match test resources, and connect test premises and effects to form a test path plan. Under the guidance of the knowledge graph constructed in step 1, all test paths are fully traversed to ensure a comprehensive combing of the test tool sequence. The success probability of each tool sequence is calculated according to the guidance of the knowledge graph in step 1 as the input for optimization and adjustment in step 3.

6. The method according to claim 5, wherein In step 2.2, the meaning of the vertices of the attack graph is expanded to include test tools and test effects, and the meaning of the edges of the attack graph is expanded to include the possibility of successful test execution, test execution time, or test efficiency.

7. The method according to claim 5, wherein Step 3 is as follows: Step 3.1: Assume that there are y test nodes on the test tool sequence and x optional test tools for allocation. The problem of solving the optimal allocation method is abstracted as referring to the ant colony algorithm to solve the problem of x ants placed on y vertices for optimal path selection. The test tool sequence is represented as: T = {T1, T2, T3, …, T x}, T i represents the i-th test tool, and the test node set is: V = {V1, V2, V3, …, V y}, V j represents the j-th test node; Execute the test tool on a test node and use the following matrix to replace the mapping relationship between the test tool and the test node resources: In the matrix, r ij means that the test tool T i is assigned to the test node V j for execution; The selection of test tools first requires determining a reasonable allocation relationship between the test tools and the test nodes. The time taken to select the test tools and the load balancing degree of the test nodes are indicators for measuring whether the test tools are reasonable and whether the tool chain is effective. The total execution time of a sequence of test tools is as follows: where e ij = Length i / Mips j represents the execution time of test tool T i on the test node resource V j ; The following improvements are made to the pheromone concentration update formula of the ant colony algorithm: the local pheromone update formula is improved to Δτ ij (t) = D / time ij , and the global pheromone update formula is Δτ ij '(t) = D / besttime ij , where D is a constant, time ij represents the completion time when the test node V j executes the test tool T i , besttime ij represents the shortest completion time when the test node V j executes the test tool T i ; Based on the improved ant colony algorithm, it is dynamically adjusted according to the situation at each test tool selection stage to select a better tool and record the results. If a test tool sequence can complete the test work, the test tool sequence is recorded. If it is not successful, it is not recorded, and it returns to the source point along the original path in reverse, destroying this path, and updating the pheromone Δτ ij (t). After the pheromone is updated, the ants start from the source point again and continue to search for the construction of the test tool sequence. After an optimal test tool sequence is constructed, it is recorded, and the improved ant colony algorithm is continuously called to construct the test tool sequence. When the same test tool sequence appears, it reversely retreats, contaminates the selection of the test tool in the last step of the sequence, so as to construct the optimal test tool chain in the remaining solution space and achieve full coverage of the test path; Step 3.2: Perform load balancing selection of test tools through weighted round-robin method; Understanding the execution status of the test tool as performance, the selection of the test tool can be understood as selecting the test tool with the best performance from the set of test tool types to be selected. Assigning permissions to the test tool includes two load balancing weights, weight and effective_weight. Among them, weight is the initial weight of the test tool, which remains fixed after assignment. The assignment of the initial weight is comprehensively evaluated based on the execution time e of the test tool calculated in step 3.1 ij and the prerequisite Pre of the test mode defined in step 2.

1. Effective_weight is the effective weight of the test tool, with an initial value of weight. After the test tool is selected and called and is in the in-use state, the effective weight of the test tool will be reduced. If the test tool is in the fault state, the effective weight will also be reduced. After that, when the test tool is released or the fault is resolved, the effective weight will gradually increase until it returns to weight. The tool load balancing selection method is to select the test tool with the highest value from the test tool set according to the effective_weight value, which is the test tool selection result corresponding to the current test node.

8. The method according to claim 7, wherein Step 4 specifically optimizes and adjusts the test effect and test path feedback dynamically according to the dynamic changes of the test information during the test process, and uses the adjustment results to dynamically update the test requirements of step 1, the matching correlation between the test behavior and the test tool, the attack graph of step 2, the pheromone concentrations of the two ant colony algorithms in step 3, and the load balancing weight in step 3. These parameters form a feedback mechanism to improve the calculation methods of steps 1 to 3, and optimize and improve the planning scheme of the next test tool.

9. A system for implementing the method according to any one of claims 1 to 8.

10. Application of the method according to any one of claims 1 to 8 in the field of network security technology.

Citation Information

Patent Citations

  • Method of preparation and use of polydiacetylene-based nanoparticles for the sensing of analytes

    WO2018220644A1

  • Double-resource die job shop scheduling optimization method based on ammas-ga nested algorithm

    WO2022000924A1