A war zone generation method and device for visualizing network security attack and defense situation

By dividing the war zones on the terrain area and determining the display war zones based on the number and priority of network terminals, the problem that the offensive and defense drill process cannot be visually displayed is solved, and visual display of the offensive and defense situation in the network security and adaptive battle zone allocation are realized.

CN115189907BActive Publication Date: 2025-08-12QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210567768.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-23
Publication Date
2025-08-12
Estimated Expiration
2042-05-23

AI Technical Summary

Technical Problem

The process of offensive and defense drills in the existing technology cannot be visually displayed, resulting in the inability to comprehensively evaluate network security protection capabilities and emergency response capabilities.

Method used

By dividing a fixed area as a war zone on a predetermined terrain area, and determining the distributed display war zone based on the number of network terminals and the priority of the war zone, combining texture filling and display control of additional areas, the generation and visualization of the war zone is achieved.

Benefits of technology

It realizes an intuitive display of offensive and defensive situations, and can adaptively allocate the war zone according to the offensive and defensive scale, improving the visual effect of offensive and defensive drills.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115189907B_ABST
    Figure CN115189907B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a battle zone generation method and apparatus for visualizing network security attack and defense situations. The method includes: pre-marking a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range; the at least one fixed area serving as at least one battle zone; the battle zones having different priorities, the battle zones used to display network terminals participating in network attack and defense confrontations or network terminals participating in network attacks on predetermined targets; obtaining the number of network terminals participating in the attack and defense; and determining the battle zone used to display the network terminals based on the number of network terminals and the priority of the battle zones. This application achieves battle zone generation by dividing terrain areas and controlling the display of different areas, facilitating adaptive allocation of battle zones based on the scale of the attack and defense to display the attack and defense situation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular to a battle zone generation method and device for visualizing network security attack and defense situations. Background Art

[0002] The purpose of attack and defense drills is to comprehensively assess the overall security protection capabilities of the target network, test the effectiveness of the defender's security monitoring, protection and emergency response mechanisms and measures, and train the emergency response team to improve its ability to handle security incidents.

[0003] The rules of attack and defense drills are generally that the attacker can use any feasible means to break into the target's intranet or take control of the target. The target will then withdraw from the public target, and other attackers will no longer be able to submit reports about the target. This often results in the final attack result, and the entire attack and defense drill process cannot be intuitively displayed. Summary of the Invention

[0004] In response to the problems in the prior art, embodiments of the present invention provide a method and apparatus for generating a battle zone for visualizing the attack and defense situation of network security.

[0005] Specifically, the embodiments of the present invention provide the following technical solutions:

[0006] In a first aspect, an embodiment of the present invention provides a battle zone generation method for visualizing network security attack and defense situations, comprising: pre-marking a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in network attack and defense confrontations or for distributing and displaying network terminals participating in network attacks on predetermined targets; obtaining the number of network terminals participating in the attack and defense; and determining the battle zone for distributing and displaying the network terminals based on the number of the network terminals and the priority of the battle zones.

[0007] Furthermore, determining the battle zone for distributing and displaying the network terminals based on the number of the network terminals and the priority of the battle zone includes: judging whether the number of the network terminals is within a first preset range, the first preset range being a range less than / equal to a first predetermined threshold; if within the first preset range, distributing and displaying the network terminals in the first battle zone, which has the highest priority, and filling other battle zones with textures.

[0008] Furthermore, the method further includes: marking points around a predetermined terrain area in advance, constructing at least one additional area, and hiding the display.

[0009] Furthermore, the method further includes: determining whether a preset condition is satisfied, and if so, triggering display of at least one additional area.

[0010] Furthermore, the method also includes: determining whether the number of the network terminals is within a second preset range, the second preset range being a range greater than a first preset threshold and less than / equal to a second preset threshold; if within the second preset range, triggering the display of an additional area as a slave area, and displaying the distribution of network terminals beyond the first predetermined threshold in the slave area.

[0011] Furthermore, the method further includes: triggering the display of an additional area based on the attack and defense records of the network terminals participating in the attack and defense as a slave area, and distributing and displaying the network terminals selected based on the attack and defense records in the slave area.

[0012] Furthermore, the area added based on the attack and defense record triggering display of the network terminal participating in the attack and defense, as a slave area, includes: determining the heat value of the corresponding network terminal based on at least one of the number of attacks, number of defenses, attack success rate and defense success rate in the attack and defense record of the network terminal participating in the attack and defense; judging whether the heat value is greater than or equal to a preset threshold value, if the heat value is greater than or equal to the preset threshold value, triggering the display of the slave area, and displaying the network terminal whose heat value is greater than or equal to the preset threshold value in the slave area.

[0013] Furthermore, the method further comprises: triggering the display of the slave area according to an instruction for performing special display on the network terminal, and displaying the network terminal requiring special display in the slave area.

[0014] In a second aspect, an embodiment of the present invention further provides a battle zone generation device for visualizing network security attack and defense situation, comprising: a first processing module, for pre-marking a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in network attack and defense confrontations or for distributing and displaying network terminals participating in network attacks on predetermined targets; a second processing module, for obtaining the number of network terminals participating in attack and defense; a third processing module, for determining the battle zones for distributing and displaying the network terminals based on the number of the network terminals and the priority of the battle zones.

[0015] In a third aspect, an embodiment of the present invention further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, the steps of the battle zone generation method for visualizing the network security attack and defense situation as described in the first aspect are implemented.

[0016] In a fourth aspect, an embodiment of the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the battle zone generation method for visualizing the network security attack and defense situation as described in the first aspect.

[0017] In a fifth aspect, an embodiment of the present invention further provides a computer program product having executable instructions stored thereon, which, when executed by a processor, enables the processor to implement the steps of the battle zone generation method for visualizing the network security attack and defense situation described in the first aspect.

[0018] Embodiments of the present invention provide a battle zone generation method and device for visualizing network security attack and defense situations. The present invention pre-marks a predetermined terrain area to divide the terrain area into at least one fixed area, each of which includes at least a certain range. The at least one fixed area serves as at least one battle zone, each of which has different priorities. The battle zone is used to distribute and display network terminals participating in network attack and defense confrontations or network terminals participating in network attacks on predetermined targets. The method also obtains the number of network terminals participating in the attack and defense, and determines the battle zone for distributing and displaying the network terminals based on the number of network terminals and the priority of the battle zone. This application achieves battle zone generation through the division of terrain areas and the display control of different areas, which facilitates the adaptive allocation of battle zones based on the scale of the attack and defense to display the attack and defense situation. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 This is a flow chart of an embodiment of a method for generating a battle zone for visualizing network security attack and defense situations according to the present invention;

[0021] Figure 2 This is a schematic structural diagram of an embodiment of a battle zone generation device for visualizing network security attack and defense situations according to the present invention;

[0022] Figure 3 It is a schematic diagram of the structure of an electronic device embodiment of the present invention. DETAILED DESCRIPTION

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0024] Figure 1 This is a flow chart of an embodiment of a method for generating a battle zone for visualizing network security attack and defense situation. Figure 1 As shown, the method of the embodiment of the present invention includes:

[0025] S101, dotting a predetermined terrain area in advance to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in a network attack and defense confrontation or for distributing and displaying network terminals participating in a network attack on a predetermined target.

[0026] In some embodiments, custom content markup can be used to mark predetermined terrain areas by modifying XHTML+CSS. XHTML+CSS is a web design standard and a web page layout method. Unlike traditional table-based layout methods, it can separate web page content from presentation.

[0027] As an example, each fixed area includes flat land, mountains, rivers, etc. Flat land can be used to set up a battle zone, so ensuring that the fixed area includes at least a certain range of flat land is to ensure that each fixed area can be used as a battle zone.

[0028] As an example, the first main area and other main areas are used to display attack and defense teams. The first main area can also be used to display a specific target or scene, and the other main areas can be used to display targets or scenes different from those displayed in the first main area.

[0029] As an example, the first main area and other main areas are fixedly displayed in the interface.

[0030] The present invention does not limit the shape of the predetermined terrain area.

[0031] In an application scenario, network terminals participating in a network attack and defense confrontation may attack each other, and the battle zone is used to distribute and display the network terminals participating in the network attack and defense confrontation.

[0032] In another application scenario, network terminals participating in the network attack and defense confrontation attack the same target, and the battle zone is used to distribute and display the network terminals participating in the network attack on the predetermined target.

[0033] As an example, the priority of war zones can be set based on different trigger conditions.

[0034] S102, obtaining the number of network terminals participating in the attack and defense.

[0035] The purpose of obtaining the number of network terminals participating in the attack and defense is to allocate the network terminals participating in the attack and defense to the first main area and / or other main areas according to the data. In the attack and defense scenario, the network terminals participating in the attack and defense are the attack and defense teams.

[0036] As an example, the number of network terminals participating in the attack and defense may be obtained based on the IP addresses, login information, and the like of the network terminals.

[0037] S103: Determine the battle zones for distributing and displaying the network terminals according to the number of the network terminals and the priorities of the battle zones.

[0038] As an example, the battle zones used to distribute and display the network terminals are A, B, C, and D. If the number of network terminals is 0 to 25, they are preferentially allocated to battle zone A (battle zone A can display up to 25 network terminals); if the number of network terminals is 25 to 60, 25 network terminals are first allocated to battle zone A, and then the remaining network terminals are allocated to battle zones B, C, and D.

[0039] In some optional implementations, determining the battle zone for distributing and displaying the network terminals based on the number of the network terminals and the priority of the battle zone includes: judging whether the number of the network terminals is within a first preset range, the first preset range being a range less than / equal to a first predetermined threshold; if within the first preset range, displaying the network terminals in the first battle zone, which has the highest priority, and filling other battle zones with textures.

[0040] For example, the first preset range is 0 to 25, and the first predetermined threshold is 25. If the number is 15, then within the first preset range, the other main areas are filled with textures. Texture filling can be done by stretching an image to fill the area, repeating an image to fill the area, or filling the area according to a custom pattern. If the number is 30, then it is outside the first preset range, and the network terminal can be displayed in the first main area and the other main areas, and the blank portions of the areas are filled with textures.

[0041] Different display conditions for battle zones and triggering battle zones are set to realize the visualization of battle zones in attack and defense drills, which is conducive to more intuitive display of attack and defense drill scenarios.

[0042] An embodiment of the present invention provides a battle zone generation method for visualizing network security attack and defense situations. This method pre-marks a predetermined terrain area to divide it into at least one fixed area, each of which includes at least a certain range. The at least one fixed area serves as at least one battle zone, each with different priorities. The battle zone is used to display network terminals participating in a network attack and defense confrontation or participating in a network attack against a predetermined target. The method also obtains the number of participating network terminals and determines the battle zone in which to display the terminals based on the number of terminals and the battle zone priorities. By dividing the terrain area and controlling the display of different areas, battle zones are generated, facilitating adaptive allocation of battle zones based on the scale of the attack and defense to visualize the attack and defense situation.

[0043] In some optional implementations, the method further includes: pre-marking points around a predetermined terrain area, constructing at least one additional area, and hiding the display.

[0044] For example, additional areas can be constructed by dotting around a predetermined terrain area based on user input or parameter triggering. The additional areas can be filled in according to specific needs, such as to display teams.

[0045] In some optional implementations, the method further includes: determining whether a preset condition is satisfied, and if so, triggering display of at least one additional area.

[0046] In some embodiments, the pre-set condition can be based on the number of terminals to be displayed. For example, if the number of terminals to be displayed is greater than 50, the display of at least one additional area is triggered. Alternatively, the condition can be based on other conditions, such as obtaining the IP address of a network terminal and triggering the display of at least one additional area based on the IP address of the network terminal. Specific conditions can be set as needed.

[0047] In some optional implementations, the method further includes: determining whether the number of the network terminals is within a second preset range, the second preset range being a range greater than the first preset threshold and less than / equal to the second preset threshold; if within the second preset range, triggering the display of the additional area as a slave area, and displaying the distribution of network terminals beyond the first predetermined threshold in the slave area.

[0048] As an example, the second preset range is 25 to 50, the second predetermined threshold is 50, and if the number is 30, then the number 30 is within the second preset range, triggering the display of the additional area as the slave area.

[0049] In an application scenario, the number of teams (network terminals) participating in the attack and defense deduction is 30, which meets the second preset range of 25 to 50, and the slave area is displayed.

[0050] In some implementations, areas added in real time by a preset algorithm may also be used as slave areas.

[0051] In some optional implementations, the method further includes: triggering display of an additional area based on attack and defense records of network terminals participating in the attack and defense as a slave area, and displaying the distribution of network terminals selected based on the attack and defense records in the slave area.

[0052] As an example, the attack and defense records include the number of attacks by each network terminal participating in the attack and defense drill, the success rate of each attack, the success rate of defense, etc.

[0053] In some embodiments, the display of the additional area can be triggered based on preset rules and attack and defense records. For example, the preset rule is that if the number of attacks by the network terminal exceeds a preset number, the additional area is triggered to be displayed as a slave area.

[0054] In some optional implementations, the additional area triggered for display based on the attack and defense records of the network terminals participating in the attack and defense, as a slave area, includes: determining the heat value of the corresponding network terminal based on at least one of the number of attacks, number of defenses, attack success rate and defense success rate in the attack and defense records of the network terminals participating in the attack and defense; judging whether the heat value is greater than or equal to a preset threshold value, and if the heat value is greater than or equal to the preset threshold value, triggering the display of the slave area, and displaying the network terminals whose heat values are greater than or equal to the preset threshold value in the slave area.

[0055] Continuing with the above example, the attack and defense record includes the number of attacks per network terminal participating in the drill, the success rate of each attack, and the success rate of the defense. This number, success rate, and defense success rate can be weighted and summed to create a heat value. The heat values of each network terminal can then be compared to determine whether they are greater than or equal to a preset threshold. If so, the display of the slave area is triggered. Alternatively, the value of a parameter in the attack and defense record can be monitored in real time and used as the heat value.

[0056] In some optional implementations, the method further includes: triggering display of the slave area according to an instruction for performing special display on the network terminal, and displaying the network terminal requiring special display in the slave area.

[0057] As an example, a user can click a button on the screen to trigger the display of the secondary area. In an application scenario, the user first selects a target to be displayed, and then clicks OK to trigger the display of the secondary area, which is used to display the target selected by the user.

[0058] Figure 2 This is a schematic diagram of the structure of an embodiment of a battle zone generation device for visualizing network security attack and defense situation. Figure 2 As shown, the device comprises:

[0059] A first processing module 201 is configured to pre-mark a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, and the battle zones being used to distribute and display network terminals participating in a network attack and defense confrontation or network terminals participating in a network attack on a predetermined target;

[0060] The second processing module 202 is used to obtain the number of network terminals participating in the attack and defense;

[0061] The third processing module 203 is used to determine the battle zones for distributing and displaying the network terminals according to the number of the network terminals and the priorities of the battle zones.

[0062] Optionally, the third processing module 203 is further used to: determine whether the number of the network terminals is within a first preset range, the first preset range being a range less than / equal to a first predetermined threshold; if within the first preset range, the network terminal distribution is displayed in the first battle zone, the first battle zone has the highest priority, and other battle zones are filled with textures.

[0063] Optionally, the device further comprises a fourth processing module, configured to: pre-mark points around a predetermined terrain area, construct at least one additional area, and hide and display it.

[0064] Optionally, the device further includes a fifth processing module, configured to determine whether a preset condition is satisfied, and if so, trigger the display of at least one additional area.

[0065] Optionally, the device also includes a sixth processing module, which is used to: determine whether the number of the network terminals is within a second preset range, the second preset range being a range greater than the first preset threshold and less than / equal to the second preset threshold; if it is within the second preset range, trigger the display of the additional area as a slave area, and display the distribution of network terminals beyond the first predetermined threshold in the slave area.

[0066] Optionally, the seventh processing module is used to: trigger the display of an additional area as a slave area based on the attack and defense records of the network terminals participating in the attack and defense, and display the distribution of network terminals selected based on the attack and defense records in the slave area.

[0067] Optionally, the device also includes a seventh processing module, which is also used to: determine the heat value of the corresponding network terminal based on at least one of the number of attacks, number of defenses, attack success rate and defense success rate in the attack and defense records of the network terminal participating in the attack and defense; judge whether the heat value is greater than or equal to a preset threshold value, and if the heat value is greater than or equal to the preset threshold value, trigger the display of the slave area, and display the network terminal whose heat value is greater than or equal to the preset threshold in the slave area.

[0068] Optionally, the device further includes an eighth processing module, configured to: trigger the display of the slave area according to an instruction for performing special display on the network terminal, and display the network terminal requiring special display in the slave area.

[0069] Here is an example:

[0070] Figure 3 An example of a physical structure diagram of an electronic device is shown below. Figure 3 As shown, the electronic device may include: a processor 310, a communications interface 320, a memory 330, and a communications bus 340, wherein the processor 310, the communications interface 320, and the memory 330 communicate with each other via the communications bus 340. The processor 310 may call logic instructions in the memory 330 to execute the following method: pre-marking a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in a network attack and defense confrontation or for distributing and displaying network terminals participating in a network attack on a predetermined target; obtaining the number of network terminals participating in the attack and defense; and determining the battle zone for distributing and displaying the network terminals based on the number of network terminals and the priorities of the battle zones.

[0071] In addition, the logic instructions in the above-mentioned memory 330 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0072] On the other hand, an embodiment of the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the battle zone generation method for visualizing the network security attack and defense situation provided by the above-mentioned embodiments, for example, including: pre-marking on a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area includes at least a certain range, and the at least one fixed area serves as at least one battle zone, and the battle zones have different priorities. The battle zones are used to distribute and display network terminals participating in network attack and defense confrontation or to distribute and display network terminals participating in network attacks on predetermined targets; obtaining the number of network terminals participating in attack and defense; and determining the battle zones for distributing and displaying the network terminals based on the number of the network terminals and the priority of the battle zones.

[0073] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the battle zone generation method for visualizing the network security attack and defense situation provided by the above-mentioned embodiments, for example, including: pre-marking on a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in network attack and defense confrontations or for distributing and displaying network terminals participating in network attacks on predetermined targets; obtaining the number of network terminals participating in attack and defense; and determining the battle zones for distributing and displaying the network terminals based on the number of network terminals and the priority of the battle zones.

[0074] The device embodiments described above are merely illustrative. Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, i.e., they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0075] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus the necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each embodiment or certain parts of the embodiment.

[0076] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A war zone generation method for visualizing network security attack and defense situation, characterized in that: include: Dotting a predetermined terrain area in advance to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in a network attack and defense confrontation or for distributing and displaying network terminals participating in a network attack on a predetermined target; Obtain the number of network terminals involved in attack and defense; determining, according to the number of the network terminals and the priority of the battle zones, battle zones for distributing and displaying the network terminals; The method further comprises: Determine the heat value of the corresponding network terminal according to at least one of the number of attacks, the number of defenses, the attack success rate, and the defense success rate in the attack and defense records of the network terminal participating in the attack and defense; Determine whether the heat value is greater than or equal to a preset threshold. If the heat value is greater than or equal to the preset threshold, trigger the display of the slave area, and display the network terminals whose heat values are greater than or equal to the preset threshold in the slave area; wherein, the slave area is: an additional area that is pre-dotted and constructed around a predetermined terrain area, which is displayed in a hidden manner.

2. The battle zone generation method for visualizing network security attack and defense situation according to claim 1 is further characterized in that: Determining the war zones for distributing and displaying the network terminals according to the number of the network terminals and the priorities of the war zones includes: determining whether the number of the network terminals is within a first preset range, the first preset range being a range less than / equal to a first predetermined threshold; If within the first preset range, the network terminal distribution is displayed in the first battle zone, which has the highest priority, and other battle zones are filled with textures.

3. The battle zone generation method for visualizing network security attack and defense situation according to claim 1 is further characterized in that: The method further includes: Dots are placed around a predetermined terrain area in advance to construct at least one additional area and hide the display.

4. The battle zone generation method for visualizing network security attack and defense situation according to claim 3 is further characterized in that: The method further includes: It is determined whether a preset condition is met, and if so, at least one additional area is triggered to be displayed.

5. The battle zone generation method for visualizing network security attack and defense situation according to claim 4 is further characterized in that: The method further includes: determining whether the number of the network terminals is within a second preset range, where the second preset range is a range greater than a first predetermined threshold and less than / equal to a second predetermined threshold; If it is within the second preset range, the additional area is triggered to be displayed as a slave area, and the network terminals exceeding the first predetermined threshold number are distributed and displayed in the slave area.

6. The battle zone generation method for visualizing network security attack and defense situation according to claim 4 is further characterized in that: The method further includes: An additional area is triggered to be displayed based on the attack and defense records of the network terminals participating in the attack and defense, as a slave area, and the network terminals selected based on the attack and defense records are distributed and displayed in the slave area.

7. The battle zone generation method for visualizing network security attack and defense situation according to claim 4 is further characterized in that: The method further comprises: According to the instruction for performing special display on the network terminal, the display of the slave area is triggered, and the network terminal requiring special display is displayed in the slave area.

8. A battle zone generation device for visualizing network security attack and defense situation, characterized in that: include: a first processing module configured to pre-mark a predetermined terrain area to divide the terrain area into at least one fixed area, each fixed area including at least a certain range, the at least one fixed area serving as at least one battle zone, the battle zones having different priorities, the battle zones being used to distribute and display network terminals participating in a network attack and defense confrontation or network terminals participating in a network attack on a predetermined target; The second processing module is used to obtain the number of network terminals participating in the attack and defense; a third processing module, configured to determine, based on the number of the network terminals and the priority of the battle zones, the battle zones for distributing and displaying the network terminals; The device also includes a seventh processing module, which is further used to: determine the heat value of the corresponding network terminal based on at least one of the number of attacks, number of defenses, attack success rate and defense success rate in the attack and defense records of the network terminal participating in the attack and defense; judge whether the heat value is greater than or equal to a preset threshold value, and if the heat value is greater than or equal to the preset threshold value, trigger the display of the slave area, and display the network terminals with heat values greater than or equal to the preset threshold value in the slave area; wherein, the slave area is: an additional area that is pre-dotted and constructed around a predetermined terrain area, which is displayed in a hidden manner.

9. An electronic device, characterized in that: include: processor, memory, and bus, wherein The processor and the memory communicate with each other via the bus; The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the steps of the battle zone generation method for visualizing network security attack and defense situation as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium, characterized in that The non-transitory computer-readable storage medium stores computer instructions, which enable a computer to execute the steps of the battle zone generation method for visualizing the network security attack and defense situation according to any one of claims 1 to 7.

11. A computer program product comprising computer-executable instructions, characterized in that: When executed, the instructions are used to perform the steps of the battle zone generation method for visualizing the network security attack and defense situation as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Application display method and device, terminal and readable storage medium

    CN109164959A

  • Security situation monitoring method and system

    CN110855506A