Network security attack and defense drill system, method and readable storage medium
By building a network security attack and defense drill system and dynamically evaluating network equipment and scenario parameters, the problem of low efficiency in simulating dynamic attack scenarios in existing technologies has been solved, the pertinence and efficiency of network security drills have been improved, network intrusion paths have been discovered, and defense capabilities have been enhanced.
Patent Information
- Application Number
- CN202211336074.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-28
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2042-10-28
AI Technical Summary
Existing technologies are unable to effectively simulate dynamically changing network security attack scenarios, resulting in inefficient network security attack and defense drills and an inability to adapt to complex and changing business needs.
A network security attack and defense drill system is provided, which includes a setting layer, a scenario layer and a drill layer. By modeling network equipment, dynamically evaluating the drill results, simulating the network attack environment closest to actual combat, and combining preset training objectives and constraints, the drill results of the drill party are evaluated.
It has achieved more accurate discovery of network intrusion paths, revealed the structural and systemic risks of network security defense systems, and improved the level of network security protection.
Smart Images

Figure CN115694970B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network security attack and defense simulation, and in particular to a network security attack and defense drill system, method, and readable storage medium. Background Art
[0002] Network security involves protecting network hardware, software, and the data within them from accidental or malicious damage, alteration, or leakage, ensuring continuous, reliable, and normal system operation and uninterrupted network services. Broadly speaking, network security encompasses all technologies and theories related to the confidentiality, integrity, availability, authenticity, and controllability of information on a network. How to more effectively protect critical information and data and improve the security of computer network systems has become a critical issue that all computer network applications must consider and address.
[0003] Conducting cybersecurity operational drills can help improve the security of computer network systems. Conducting cybersecurity operational drills is a difficult and challenging task. Creating a simulated environment for cybersecurity operational drills is error-prone and often manual. Creating such a cybersecurity drill environment and executing drill scenarios can be accomplished using a cyber range. However, current operational-based drills are inefficient.
[0004] Existing technologies have been striving to make the process of conducting cybersecurity operational drills more efficient and less labor-intensive. These existing technologies have successfully addressed the inefficiencies in cybersecurity attack and defense drills. However, most existing technologies are limited to the deployment of the attack and defense drill infrastructure. However, evolving cybersecurity threats are dynamic, so it is necessary to model the drill scenarios to ensure sufficient adaptability to accommodate changes in scenario requirements before and after deployment. Therefore, it is necessary to develop a cybersecurity operational drill solution that can simulate a dynamically changing cybersecurity attack drill environment. This can make the cybersecurity attack drill environment closer to a real-world cyberattack scenario, making cybersecurity attack drills more targeted and the drill lifecycle more efficient, thereby addressing well-known global cybersecurity technical challenges. Summary of the Invention
[0005] The present application aims to solve at least one of the above-mentioned technical defects. In view of this, the present application provides a network security attack and defense drill system, method and readable storage medium to solve the technical defect in the prior art that it is difficult to conduct network security attack and defense simulation drills against network attacks.
[0006] A network security attack and defense drill system, the system comprising:
[0007] Setup layer, scene layer, and walkthrough layer;
[0008] in,
[0009] The setting layer is used to establish different network device models for different network devices and set various device parameters of each network device model;
[0010] The scenario layer is used to construct simulation drill scenarios, evaluate the network operations of each drill party, and change the device parameters of each network device model and the scenario parameters of the simulation drill scenarios according to the network operations of each drill party; based on the preset training objectives and combined with the preset constraints, the drill results of each drill party are dynamically evaluated;
[0011] The training layer is used to establish different network operation models for different network operations, so that each training party can use each network operation model to perform network operations on each network device model.
[0012] Preferably, the setting layer includes a network device modeling module, a condition constraint module, a parameter setting module and a comprehensive management module;
[0013] The network device modeling module is used to model the software devices and hardware devices in the network space;
[0014] in,
[0015] The device parameters of the network device model include device model, device version, device operating status, device permissions, device configuration parameters, device network connection parameters and device security protection capability parameters;
[0016] The condition constraint module is used to set the constraint conditions during the drill, wherein the constraint conditions include the ability conditions of the roles participating in the drill, financial constraints, and equipment constraints;
[0017] The parameter setting module is used to set the common parameters of the scene layer, wherein the common parameters of the scene layer include device visual parameters, rehearsal mechanism, and information sharing mechanism;
[0018] The comprehensive management module is used to manage various exercise tasks.
[0019] Preferably, the process of managing the drill task by the comprehensive management module includes:
[0020] Establishing each of the drill tasks according to the participants of each drill party of each of the drill tasks, the drill time and the corresponding simulated drill scenario;
[0021] Approve each of the exercise tasks;
[0022] Record the execution results of each of the drill tasks.
[0023] Preferably, the scenario layer includes a network security scenario module, an information intelligence module, and a situation analysis module;
[0024] The said exercise parties include an attacking party and a defending party;
[0025] in,
[0026] The network security scenario module is used to establish a training network using each of the network device models to form the simulated training scenario, and change each device parameter of each of the network device models according to the network operation of each training party;
[0027] The situation analysis module is used to continuously evaluate the simulation exercise scenario based on the preset constraints and various scenario parameters of the simulation exercise scenario, and dynamically update and display the results of each exercise party;
[0028] The information intelligence module is used to display information that is not controlled by the attacker and the defender, and to display relevant information based on third-party operations. The information that is not controlled by the attacker and the defender includes network vulnerabilities, supply chains, weather, and epidemic information.
[0029] Preferably, the drill layer includes a third-party modeling module, a network defense modeling module, and a network attack modeling module;
[0030] in,
[0031] The network defense modeling module is used to abstract actual defense actions into defense operations;
[0032] The network attack modeling module is used to abstract actual attack actions into attack operations;
[0033] The third-party modeling module is used to abstract the third-party network operations into third-party operations.
[0034] A network security attack and defense drill method, comprising:
[0035] Build simulation scenarios and models of various network devices;
[0036] For different network operations, different network operation models are established, so that each exercise party can respectively use each network operation model to perform network operations on each network device model, wherein the exercise parties include an attacker, a defender, and a third party;
[0037] Evaluate the network operations of each participant based on the simulated exercise scenario;
[0038] According to the network operation of each exercise party, changing each device parameter of each network device model and each scenario parameter of the simulated exercise scenario;
[0039] According to the preset training objectives and in combination with the preset constraints, the training results of the attacker and the defender are dynamically evaluated.
[0040] Preferably, the construction of simulation drill scenarios and various network device models includes:
[0041] Obtain information about each network device and establish different network device models for different network devices;
[0042] Setting each device parameter of each of the network device models;
[0043] A training network is established based on each of the network device models and each device parameter of each of the network device models to form the simulation training scenario.
[0044] Preferably, the evaluating the network operations of each exercise party based on the simulated exercise scenario includes:
[0045] Determine the value score of each network device based on the preset network device scoring criteria;
[0046] Determine whether each network device is controlled by each exercise party;
[0047] The scores of the network devices controlled by the attacker and the defender are determined based on the control status of the network devices by the attackers and the value scores of the network devices.
[0048] Preferably, the changing of the device parameters of the network device models and the scenario parameters of the simulated drill scenarios according to the network operations of the respective drill parties includes:
[0049] Determine the network operations of each exercise party;
[0050] Determine the parameters of the network equipment corresponding to the network operation type of each exercise party according to the network operation type of each exercise party;
[0051] Changing the parameters of the network devices corresponding to the network operation types of the respective exercisers to the device parameter states corresponding to the network operation types of the respective exercisers;
[0052] According to the device parameter status corresponding to the network operation type of each exercise party, each scenario parameter of the simulated exercise scenario is changed.
[0053] A readable storage medium stores computer-readable instructions, which, when executed by one or more processors, enable the one or more processors to implement the steps of the network security attack and defense drill method as described in any of the above introductions.
[0054] It can be seen from the technical solutions introduced above that when it is necessary to conduct network attack simulation drills, the embodiments of the present application can provide a network security attack and defense drill system. The system provided by the embodiments of the present application can include a setting layer, a scenario layer and a drill layer; wherein the setting layer can be used to establish different network device models for different network devices, and can set various device parameters of each of the network device models; the scenario layer can be used to construct simulation drill scenarios, can evaluate the network operations of each drill party, and change the various device parameters of each of the network device models and the various scenario parameters of the simulation drill scenarios according to the network operations of each drill party; the drill results of each drill party can be dynamically evaluated based on preset training objectives and combined with preset constraints; the drill layer can be used for different network operations, and can establish different network operation models, so that each drill party can use each of the network operation models to perform network operations on each of the network device models.
[0055] The network security attack and defense drill system provided in the embodiments of this application can model different network devices and, based on the dynamic changes in network device parameters, timely change the network security attack and defense drill scenario. Based on preset training objectives and preset constraints, it can dynamically evaluate the drill results of each drill participant. This can simulate a network attack environment that is closest to actual combat, help more accurately discover network intrusion paths, reveal the structural and systemic risks of network security defense systems, and guide the improvement of network security protection levels. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0057] Figure 1 A schematic diagram of an optional network security attack and defense drill system architecture provided in an embodiment of the present application;
[0058] Figure 2 A flowchart of a method for implementing network security attack and defense drills provided in an embodiment of the present application. DETAILED DESCRIPTION
[0059] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0060] Given that most current cybersecurity attack and defense drill solutions struggle to adapt to complex and ever-changing business needs, the applicant has developed a cybersecurity attack and defense drill solution. This solution models different network devices and, based on the dynamic changes in network device parameters, promptly changes the cybersecurity attack and defense drill scenario. Based on pre-set training objectives and constraints, it dynamically evaluates the drill results of each participant. This allows for the simulation of a cyberattack environment that is closest to actual combat, helping to more accurately identify network intrusion paths, revealing the structural and systemic risks of cybersecurity defense systems, and guiding the improvement of cybersecurity protection levels.
[0061] The methods provided in the embodiments of the present application can be used in a variety of general-purpose or specialized computing device environments or configurations, such as personal computers, server computers, handheld or portable devices, tablet devices, multi-processor devices, and distributed computing environments including any of the above.
[0062] An embodiment of the present application provides a network security attack and defense drill solution, which can be applied to various network security management systems, as well as various computer terminals or smart terminals. Its execution entity can be the processor or server of the computer terminal or smart terminal.
[0063] The following combination Figure 1 , introduces an optional system architecture that can realize network security attack and defense drills given in the embodiment of this application, such as Figure 1 As shown, the system architecture may include: a setting layer, a scenario layer and a drill layer.
[0064] With the growing demand for networks in human life, network security has become a key issue for the further development of various network services and applications. This is especially true since the commercialization of the Internet, with the increasing number of e-commerce businesses conducted over the Internet. As Internet technology matures, many organizations and enterprises have established their own internal networks and connected them to the Internet. Business secrets stored in e-commerce applications and corporate networks have become a primary target for attackers.
[0065] According to statistics, there are currently thousands of cyber attack methods, making network security issues extremely serious. An investigation report stated that security issues such as hacker attacks and viruses caused economic losses of trillions of dollars in 2000, and multiple cyber attacks occur every few seconds around the world.
[0066] Network security is the most important issue in network management at present. It is a very complex issue. It is not only a technical issue, but also involves many aspects such as human psychology, social environment and law.
[0067] Computer network security refers to the security of hardware, software and various data in the network system, effectively preventing various resources from being intentionally or unintentionally destroyed or illegally used.
[0068] The goal of network security management is to ensure information security in the network. The entire system should meet the following requirements:
[0069] (1) Ensure data integrity. Ensure that the data and information on the computer system are in a complete and undamaged state and can only be changed by authorized parties.
[0070] (2) Ensure the confidentiality of the system. Ensure that the system is away from dangerous states and characteristics, that is, to prevent unauthorized access to data for deliberate destruction, crime, and attack, and that access can only be made by authorized parties.
[0071] (3) Ensure the availability of data. The use of data by authorized parties cannot be prevented.
[0072] (4) Non-repudiation of information: Information cannot be denied by the person providing it.
[0073] (5) The credibility of information. Information cannot be forged by others.
[0074] (6) In actual application, network devices are the main targets of network attacks.
[0075] The targets of network attacks are mainly devices in the network.
[0076] For example, servers, routers, computer equipment.
[0077] Network security attack and defense drills need to simulate scenarios involving network devices.
[0078] Therefore, the network security attack and defense system provided in the embodiment of the present application can use the setting layer to establish different network device models for different network devices and set various device parameters of each of the network device models.
[0079] Among them, various device parameters of each of the network device models can be set according to the needs of network security attack and defense drills.
[0080] Each of the network device models may include at least one device parameter.
[0081] In actual application, parties participating in network security attack and defense drills may perform different operations on various network devices.
[0082] Different network operations have different execution results.
[0083] The network security attack and defense system provided in the embodiment of the present application can use the training layer to establish different network operation models for different network operations, so that each training party can use each network operation model to perform network operations on each network device model.
[0084] Among them, each of the network operation models can be set according to the operation of each training party on the network equipment.
[0085] As can be seen from the above description, the network security attack and defense drill system provided by the embodiment of the present application can simulate network attack and defense events that occur in real life. Therefore, the participants in the network security attack and defense drill include at least two types of drill party roles.
[0086] Therefore, the network security attack and defense system provided in the embodiment of the present application can use the scenario layer to construct a simulation drill scenario, evaluate the network operations of each drill party, and change the various device parameters of each network device model and the various scenario parameters of the simulation drill scenario according to the network operations of each drill party; it can dynamically evaluate the drill results of each drill party based on the preset training objectives and combined with the preset constraints.
[0087] For example,
[0088] The scores of each exerciser can be evaluated based on the scoring values of different devices and different data, and based on the control of different devices and data by each exerciser.
[0089] For example, the scores of each exerciser can be evaluated based on the corresponding scoring values of the server, system, and data.
[0090] For example,
[0091] Each participant who obtains the account and password of each network device can be considered to control the device and obtain the points of the device;
[0092] Situations where different parties control different data may include data being stolen or lost;
[0093] This allows statistics on the devices and data controlled by both the attacker and the defender, and thus statistics on the scores of each exercise party.
[0094] By analyzing the drill results of each drill party, we can understand the attack plan of the network attacker and the emergency defense plan made by the defender against the attacker's network attack.
[0095] Further optionally, the structure of the setting layer is described in detail below.
[0096] The setting layer may include a network device modeling module, a condition constraint module, a parameter setting module and a comprehensive management module;
[0097] in,
[0098] The network security attack and defense system provided in the embodiment of the present application can use the network device modeling module to model the software devices and hardware devices in the network space;
[0099] in,
[0100] The device parameters of the network device model may include the device model, device version, device operating status, device permissions, device configuration parameters, device network connection parameters and device security protection capability parameters of the network device.
[0101] For example, the device parameters of the network device model may be a login password of the network device, an IP address of the network device, an open network port, deployed middleware, and existing vulnerability information.
[0102] The network security attack and defense system provided in the embodiment of the present application can use the condition constraint module to set the constraint conditions during the rehearsal process.
[0103] in,
[0104] The constraints may include:
[0105] The capabilities of the characters involved in the exercise;
[0106] For example, the defender's capabilities are determined by equipment and personnel, such as whether the number of equipment is sufficient to monitor all nodes; whether the number of personnel is sufficient to monitor all equipment, etc.
[0107] Funding constraints;
[0108] For example, the defender can gain enhanced regulatory oversight, and the attacker can gain access to 0Day vulnerabilities.
[0109] Equipment constraints;
[0110] For example, the probability of a device failing can be set, as can the probability of the device being attacked from a supply chain.
[0111] Setting constraints during the drill process can enable all parties involved in the drill to participate in the drill according to the constraints.
[0112] The constraints can also provide feedback on the strength level of each exerciser and the conditions for participation of each network device.
[0113] The network security attack and defense system provided in the embodiment of the present application can use the parameter setting module to set the common parameters of the scenario layer.
[0114] The common parameters of the scene layer may include:
[0115] Equipment visual parameters, drill mechanisms, and information sharing mechanisms.
[0116] in,
[0117] The device visibility parameter may be whether the network device can be viewed by each exercise party.
[0118] Among them, the training mechanism can include turn-based, real-time and real-time turn-based.
[0119] in,
[0120] The round-based system may be: the attacking and defending parties or multiple players may perform network actions corresponding to the rules of the exercise in sequence according to the exercise rounds and the rules of the exercise.
[0121] The real-time system allows each participant to perform network actions corresponding to the rules of the exercise at any time.
[0122] The real-time round system may be a combination of two or more players participating in the exercise.
[0123] The information sharing mechanism may be as follows:
[0124] (1) As a third-party supplier, it can disclose some relevant information about the vulnerabilities of network equipment. The vulnerability information disclosed by the third-party supplier can be understood and mastered by both the attacker and the defender.
[0125] (2) It is also possible that some vulnerability information is discovered by the attacker through his own mining. In this case, the vulnerability information discovered by the attacked party is only known by the attacker, and the defender is not aware of the vulnerability information discovered by the attacked party.
[0126] in,
[0127] The network security attack and defense system provided in the embodiment of the present application can use the comprehensive management module to manage various drill tasks.
[0128] In actual application, network security attack and defense drills may include several of the aforementioned drill tasks.
[0129] Each of the drill tasks may include the participants, the time of the drill and the corresponding simulated drill scenario, drill rules, and drill results.
[0130] Further optionally, the following describes in detail the process of the comprehensive management module managing each drill task provided in the embodiment of the present application, which may include the following:
[0131] (1) Establishing each of the drill tasks according to the participants of each drill party, drill time, drill rules and corresponding simulated drill scenarios.
[0132] (2) Review and approve each of the aforementioned exercise tasks.
[0133] (3) When each corresponding drill party in each of the drill tasks participates in recording the execution results of each of the drill tasks according to the preset drill rules.
[0134] Further optionally, in actual application, the scenario layer may include a network security scenario module, an information intelligence module, and a situation analysis module;
[0135] The exercise parties may include an attacker and a defender;
[0136] The attacking party may include at least one attacker, and the defending party may include at least one defender.
[0137] As can be seen from the above description, the network security attack and defense drill system provided in the embodiment of the present application can establish different network device models for different network devices. After establishing each of the network device models, the method provided in the embodiment of the present application can also use the network security scenario module to establish a drill network using each of the network device models to form the simulated drill scenario, and change the various device parameters of each of the network device models based on the network operations of each drill party.
[0138] Among them, the network operations that can be implemented by each exercise party include at least one network operation.
[0139] For example,
[0140] The network operations that can be performed by each exercise party include:
[0141] Modify the login password of the network device, modify the IP address of the network device, modify the network port of the network device, and patch the vulnerabilities of the network device.
[0142] For example,
[0143] Through the network operations described above, you can change the weak login password to a secure password; change the IP address of a network device to another IP address, change the network port of a network device to another network port, or repair the vulnerability of the network device.
[0144] In actual application, some network device models can be a data structure with parameters, and some network operations can be a type of function. In actual operation, each exercise party can use these network operations to implement function call data structures to change the data in the data structure of certain network devices or change the parameters of the network devices.
[0145] From the above introduction, it can be seen that the network security attack and defense drill system provided in the embodiment of the present application can evaluate the network operations of each drill party, and change the various device parameters of each network device model and the various scenario parameters of the simulated drill scenario according to the network operations of each drill party; it can dynamically evaluate the drill results of each drill party based on preset training objectives and combined with preset constraints.
[0146] In actual application, the situation analysis module can be used to continuously evaluate the simulation exercise scenario based on the preset constraints and various scenario parameters of the simulation exercise scenario, and dynamically update and display the results of each exercise party.
[0147] For example, in actual application, when each of the said exercise parties is conducting a simulation exercise, the situation analysis module can dynamically change the parameters of each of the said network devices according to preset constraints, for example, according to the strength level of each of the said exercise parties and the participation conditions of each of the said network devices.
[0148] Since the simulation drill scenario is a scenario constructed based on the parameters of each network device, when the parameters of each network device change dynamically, the various scenario parameters of the simulation drill scenario can change dynamically along with the parameters of each network device.
[0149] Therefore, the situation analysis module can continuously evaluate the simulation exercise scenario based on the preset constraints and various scenario parameters of the simulation exercise scenario, and dynamically update and display the results of each exercise party.
[0150] From the above introduction, we can see that based on the information sharing mechanism, during the drill process, some information can be shared by all drill parties, and some information can be understood by some drill parties, but some drill parties do not have the authority to understand it.
[0151] Based on this, the network security attack and defense system provided in the embodiment of the present application can use the information intelligence module to display information that is not controlled by the attacker and the defender, and display relevant information based on third-party operations, wherein the information that is not controlled by the attacker and the defender includes network vulnerability information, supply chain information, weather information, and epidemic information.
[0152] Further optionally, in actual application, the rehearsal layer may include a third-party modeling module, a network defense modeling module, and a network attack modeling module;
[0153] in,
[0154] The network security attack and defense system provided in the embodiment of the present application can use the network defense modeling module to abstract actual defense actions into defense operations;
[0155] The network security attack and defense system provided in the embodiment of the present application can use the network attack modeling module to abstract actual attack actions into attack operations;
[0156] The network security attack and defense system provided in the embodiment of the present application can use the third-party modeling module to abstract the third-party network operations into third-party operations.
[0157] The network security attack and defense system provided in the embodiments of the present application can utilize various modeling modules to model the various operations of each exerciser. This allows the network operation model corresponding to each exerciser to be determined. This helps analyze the exercise results of each exerciser based on their network operations.
[0158] As can be seen from the technical solutions described above, the network security attack and defense system provided by the embodiments of this application can model different network devices and, based on the dynamic changes in network device parameters, timely change the network security attack and defense drill scenarios. Based on preset training objectives and combined with preset constraints, it dynamically evaluates the drill results of each drill participant. This can simulate a network attack environment that is closest to actual combat, helping to more accurately discover network intrusion paths, revealing the structural and systemic risks of network security defense systems, and guiding the improvement of network security protection levels.
[0159] The following combination Figure 2 , introduces the process of the network security attack and defense drill method given in the embodiment of this application, such as Figure 2 As shown, the process can include the following steps:
[0160] Step S101: construct a simulation scenario and various network device models.
[0161] Specifically, as can be seen from the above introduction, a network attack and defense drill involves a drill scenario and at least one network device.
[0162] Network security attack and defense drills need to simulate scenarios involving various network devices.
[0163] Therefore, the method provided in the embodiment of the present application can construct simulation drill scenarios and various network device models for network attack and defense drills.
[0164] So that each network device model can be used to model each network device to form a training network, so that each network model and the formed training network can be used to construct a simulation exercise scenario.
[0165] Step S102 : establishing different network operation models for different network operations, so that each exerciser can respectively use each network operation model to perform network operations on each network device model, wherein the exercisers include an attacker, a defender, and a third party.
[0166] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can construct the simulation drill scenario and each of the network device models.
[0167] The simulation exercise scenario may include at least one scenario parameter.
[0168] Each of the network device models may include at least one device parameter.
[0169] In actual application, the network security simulation exercise may include at least one exerciser, and each exerciser participating in the network security attack and defense exercise may perform different operations on each network device.
[0170] Different network operations have different execution results.
[0171] Therefore, the method provided in the embodiment of the present application can establish different network operation models for different network operations, so that each training party can use each of the network operation models to perform network operations on each of the network device models, wherein the training parties can include attackers, defenders and third parties.
[0172] Step S103: Evaluate the network operation of each exercise party based on the simulated exercise scenario.
[0173] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can construct the simulation drill scenario and each of the network device models.
[0174] The method provided in the embodiment of the present application can establish different network operation models for different network operations, so that each training party can use each of the network operation models to perform network operations on each of the network device models.
[0175] Based on this, after determining the simulation drill scenario, the method provided in the embodiment of the present application can evaluate the network operations of each drill party based on the simulation drill scenario.
[0176] For example,
[0177] The network operations that can be performed by each exercise party include:
[0178] Modify the login password of the network device, modify the IP address of the network device, modify the network port of the network device, and patch the vulnerabilities of the network device.
[0179] For example,
[0180] Through the network operations described above, you can change the weak login password to a secure password; change the IP address of a network device to another IP address, change the network port of a network device to another network port, or repair the vulnerability of the network device.
[0181] In actual application, some network device models can be a data structure with parameters, and some network operations can be a type of function. In actual operation, each exercise party can use these network operations to implement function call data structures to change the data in the data structure of certain network devices or change the parameters of the network devices.
[0182] The method provided in the embodiment of the present application can understand whether each exercise party is performing defense or attack based on the network operations of each exercise party.
[0183] Step S104 , changing the device parameters of the network device models and the scenario parameters of the simulated training scenarios according to the network operations of the training parties.
[0184] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can evaluate the network operations of each exercise party based on the simulated exercise scenario.
[0185] Each drill party performs network operations on each network device, and the status of each network device will change.
[0186] Furthermore, the device parameters of each network device model can be further changed based on the network operations of each drill party. Since the various scenario parameters of the simulated drill scenario are related to the drill network formed by each network device, when the various device parameters of each network device model are changed, the various scenario parameters of the simulated drill scenario will also dynamically change accordingly. The various scenario parameters of the simulated drill scenario can be further changed based on the various device parameters of each network device model.
[0187] Step S105 , dynamically evaluating the training results of the attacker and the defender according to the preset training objectives and in combination with the preset constraints.
[0188] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can change the various device parameters of each of the network device models and the various scenario parameters of the simulated training scenario according to the network operations of each training party.
[0189] After changing the various device parameters of the network device models and the various scenario parameters of the simulation exercise scenarios, the exercise results of the attacker and the defender can be dynamically evaluated based on the preset training objectives and in combination with the preset constraints.
[0190] As can be seen from the technical solutions described above, the method provided in the embodiments of this application can model different network devices and, based on the dynamic changes in network device parameters, timely change the network security attack and defense drill scenario. Based on the preset training objectives and combined with the preset constraints, the drill results of each drill party can be dynamically evaluated. This can simulate the network attack environment that is closest to actual combat, help to more accurately discover network intrusion paths, reveal the structural and systemic risks of network security defense systems, and guide the improvement of network security protection levels.
[0191] As can be seen from the above description, the method provided in the embodiment of the present application can construct a simulation drill scenario and various network device models. The following describes the process, which may include the following steps:
[0192] Step S201: Acquire information of each network device and establish different network device models for different network devices.
[0193] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can construct the simulation drill scenario and various network devices.
[0194] The simulation drill scenario includes various scenario parameters. Each of the network devices includes a network device parameter.
[0195] Each scenario parameter of the simulation drill scenario is related to each network device parameter of each network device.
[0196] Therefore, in order to construct the simulation drill scenario and each network device, information of each network can be obtained, and the network security drill scenario required for the drill is constructed to include at least one network device.
[0197] Therefore, after acquiring each network device, different network device models can be established for different network devices.
[0198] Step S202: setting device parameters of each of the network device models.
[0199] Specifically, it can be seen from the above introduction that the method provided in the embodiment of the present application can establish different network device models for different network devices.
[0200] Each of the network device models includes at least one device parameter.
[0201] Therefore, after establishing each of the network device models, each device parameter of each of the network device models may be further set.
[0202] So that the simulation exercise network can be constructed based on the various device parameters of each of the network device models.
[0203] Step S203: establishing a training network according to each of the network device models and each of the device parameters of the network device models to form the simulation training scenario.
[0204] Specifically, it can be seen from the above introduction that the method provided in the embodiment of the present application can establish different network device models for different network devices.
[0205] After determining the network devices required for the simulation drill scenario, a drill network may be established based on each of the network device models and each device parameter of each of the network device models to form the simulation drill scenario.
[0206] As can be seen from the above introduction, the method provided in the embodiment of the present application can obtain the information of each network device, establish different network device models for different network devices; set the various device parameters of each of the network device models; establish a drill network based on each of the network device models and the various device parameters of each of the network device models to form the simulated drill scenario. This allows the network security attack and defense drill scenario to be changed in a timely manner based on modeling different network devices and the dynamic changes in the parameters of the network devices. The drill results of each drill party can be dynamically evaluated based on the preset training objectives and the preset constraints. This can simulate the network attack environment that is closest to actual combat, help to more accurately discover network intrusion paths, reveal the structural and systemic risks of network security defense systems, and guide the improvement of network security protection levels.
[0207] As can be seen from the above description, the method provided in the embodiment of the present application can evaluate the network operations of each exercise party based on the simulated exercise scenario. The following describes the process, which may include the following steps:
[0208] Step S301: Determine the value score of each network device according to a preset network device scoring standard.
[0209] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can construct each network device model for each network device used to construct a simulation exercise scenario.
[0210] In the simulated drill scenario, different drill tasks can be set so as to evaluate the strength level of each drill party through its specific performance in executing different drill tasks, thereby dynamically evaluating the drill results of each drill party.
[0211] Therefore, in order to better evaluate the strength level of each exercise party or the participation of each exercise party, after constructing each of the network device models, the value score of each network device can be further determined based on the preset network device scoring standard.
[0212] Step S302: determine whether each network device is controlled by each training party.
[0213] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can determine the value score of each network device based on the preset network device scoring standard.
[0214] The value score of each network device can represent the value of each network device.
[0215] Each exerciser can obtain the value score corresponding to the network equipment controlled by it based on the network equipment controlled by it.
[0216] Therefore, after determining the value score of each network device, we can further judge the control of each network device by each exercise party based on the parameter status of each network device so that we can evaluate the participation strength of each exercise party and the final exercise results based on the score of each exercise party.
[0217] For example, it is possible to determine which training party controls the network device by judging which training party controls the account and password of each network device.
[0218] If the account and password of a network device are obtained by the attacker, the network device is considered to be controlled by the attacker, and the attacker obtains the corresponding value score of the network device.
[0219] On the contrary, if the account and password of a network device are known to the defender, the network device is considered to be controlled by the defender, and the defender obtains the corresponding value score of the network device.
[0220] Step S303 : determining the scores of the network devices controlled by the attacker and the defender respectively according to the control status of each network device by each exerciser and the value score of each network device.
[0221] Specifically, from the above introduction, it can be seen that the method provided in the embodiment of the present application can determine the situation in which each network device is controlled by each training party, thereby determining the situation of the network devices controlled by each training party.
[0222] From the above introduction, we can see that each network device has a corresponding value score.
[0223] After determining the network devices controlled by each participant, the scores of the network devices controlled by the attacker and defender can be determined based on the control status of each participant and the value score of each network device. The final results of the exercise can be evaluated based on the scores of the network devices controlled by the attacker and defender.
[0224] As can be seen from the technical solutions introduced above, the method provided in the embodiment of the present application can evaluate the network operations of each exerciser based on the simulated exercise scenario. This allows the network operations of each exerciser to be evaluated based on the simulated exercise scenario. This allows the network equipment to be modeled and the network equipment parameters to be dynamically changed in a timely manner. The network attack and defense drill scenarios can be dynamically evaluated based on the preset training objectives and the preset constraints. This allows the simulation of a network attack environment that is closest to actual combat, helping to more accurately discover network intrusion paths, revealing the structural and systemic risks of network security defense systems, and guiding the improvement of network security protection levels.
[0225] As can be seen from the above introduction, the method provided in the embodiment of the present application can change the various device parameters of each network device model and the various scenario parameters of the simulated drill scenario according to the network operation of each drill party. The following describes the process, which may include the following steps:
[0226] Step S401: Determine the network operation of each training party.
[0227] Specifically, it can be seen from the above introduction that the method provided in the embodiment of the present application can construct different network operation models according to the operations performed by each training party on different network devices or data.
[0228] Therefore, after constructing different network operation models, the specific network operation information of each exercise party can be determined during the exercise.
[0229] For example, the network devices corresponding to the network operations performed by each exerciser and the specific operation contents performed by each exerciser may be determined.
[0230] This allows you to adjust the parameters of the corresponding network equipment based on the network operation type of each drill party.
[0231] Step S402: determining parameters of network devices corresponding to the network operation types of the respective exercisers according to the network operation types of the respective exercisers.
[0232] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can determine the network equipment corresponding to the network operations performed by each training party and the specific operation content performed by each training party.
[0233] As can be seen from the above description, the parameter changes of each of the network devices are related to the network operations performed by each training party on each of the network devices.
[0234] As different drill parties perform different network operations on different network devices, the parameters of each network device can be dynamically adjusted.
[0235] After determining the network devices corresponding to the network operations performed by each exerciser and the specific operations performed by each exerciser, parameters of the network devices corresponding to the network operation types of each exerciser may be determined based on the network operation types of each exerciser.
[0236] Step S403: Change the parameters of the network devices corresponding to the network operation types of the respective training parties to the device parameter states corresponding to the network operation types of the respective training parties.
[0237] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can determine the parameters of the network equipment corresponding to the network operation type of each training party based on the network operation type of each training party.
[0238] The changes in the parameters of the network devices corresponding to the network operation types of the respective exercisers are related to the specific network operations implemented by the respective exercisers.
[0239] Therefore, after each exerciser performs different network operations on each network device, the parameters of the network device corresponding to the network operation type of each exerciser can be further changed to the device parameter state corresponding to the network operation type of each exerciser.
[0240] Step S404 : changing each scenario parameter of the simulated training scenario according to the device parameter status corresponding to the network operation type of each training party.
[0241] Specifically, as can be seen from the above introduction, the method provided in the embodiment of the present application can change the parameters of the network device corresponding to the network operation type of each training party to the device parameter state corresponding to the network operation type of each training party.
[0242] From the above introduction, it can be seen that the various scenario parameters of the simulated drill scenario are related to the various network device parameters. Therefore, when the device parameter status corresponding to the network operation type of each drill party changes, the various scenario parameters of the simulated drill scenario can be further changed according to the device parameter status corresponding to the network operation type of each drill party.
[0243] As can be seen from the technical solutions introduced above, the method provided in the embodiment of the present application can change the various device parameters of each network device model and the various scenario parameters of the simulated drill scenario according to the network operations of each drill party. In this way, by modeling different network devices and dynamically changing the parameters of the network devices, the scenario of the network security attack and defense drill can be changed in time, and the game dynamics of each drill party can be determined based on the preset training objectives and combined with the preset constraints to evaluate the drill results of each drill party. In this way, the network attack environment closest to actual combat can be simulated, which helps to more accurately discover the network intrusion path, reveal the structural and systemic risks of the network security defense system, and guide the improvement of the network security protection level.
[0244] An embodiment of the present application also provides a readable storage medium, which can store a program suitable for execution by a processor, and the program is used to: implement various processing flows of the aforementioned terminal in the network security attack and defense drill plan.
[0245] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0246] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0247] The above description of the disclosed embodiments is intended to enable those skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. The various embodiments may be combined with one another. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A network security attack and defense drill system, characterized in that: The system includes: Setup layer, scene layer, and walkthrough layer; The setting layer is used to establish different network device models for different network devices and set various device parameters of each network device model; The training layer is used to establish different network operation models for different network operations, so that each training party can use each network operation model to perform network operations on each network device model; The scenario layer is used to construct a simulation drill scenario, evaluate the network operation of each drill party, and change the various device parameters of each network device model and the various scenario parameters of the simulation drill scenario according to the network operation of each drill party; the specific steps include: determining the network operation of each drill party; determining the parameters of the network device corresponding to the network operation type of each drill party according to the network operation type of each drill party; changing the parameters of the network device corresponding to the network operation type of each drill party to the device parameter state corresponding to the network operation type of each drill party; changing the various scenario parameters of the simulation drill scenario according to the device parameter state corresponding to the network operation type of each drill party; wherein, when the network device model is a data structure with parameters, the network operation is a type of function, and the function is used to call the data structure to change the data in the data structure of the network device model or change the parameters of the network device model; The scenario layer is also used to dynamically evaluate the exercise results of each exercise party based on preset training objectives and preset constraints; wherein the constraints include the ability conditions of the roles participating in the exercise, financial constraints, and equipment constraints.
2. The system according to claim 1, wherein: The setting layer includes a network device modeling module, a condition constraint module, a parameter setting module and a comprehensive management module; The network device modeling module is used to model the software devices and hardware devices in the network space; The device parameters of the network device model include device model, device version, device operating status, device permissions, device configuration parameters, device network connection parameters and device security protection capability parameters; The condition constraint module is used to set the constraint conditions during the exercise; The parameter setting module is used to set the common parameters of the scene layer, wherein the common parameters of the scene layer include device visual parameters, rehearsal mechanism, and information sharing mechanism; The comprehensive management module is used to manage various exercise tasks.
3. The system according to claim 2, characterized in that The process of managing the drill task by the comprehensive management module includes: Establishing each of the drill tasks according to the participants of each drill party of each of the drill tasks, the drill time and the corresponding simulated drill scenario; Approve each of the exercise tasks; Record the execution results of each of the drill tasks.
4. The system according to claim 1, wherein: The scenario layer includes a network security scenario module, an information intelligence module, and a situation analysis module; The said exercise parties include an attacking party and a defending party; The network security scenario module is used to establish a training network using each of the network device models to form the simulated training scenario, and change the device parameters of each of the network device models according to the network operations of each training party; The situation analysis module is used to continuously evaluate the simulation exercise scenario based on the preset constraints and various scenario parameters of the simulation exercise scenario, and dynamically update and display the results of each exercise party; The information intelligence module is used to display information that is not controlled by the attacker and the defender, and to display relevant information based on third-party operations. The information that is not controlled by the attacker and the defender includes network vulnerabilities, supply chains, weather, and epidemic information.
5. The system according to claim 1, wherein: The drill layer includes a third-party modeling module, a network defense modeling module, and a network attack modeling module; The network defense modeling module is used to abstract actual defense actions into defense operations; The network attack modeling module is used to abstract actual attack actions into attack operations; The third-party modeling module is used to abstract the third-party network operations into third-party operations.
6. A network security attack and defense drill method, characterized in that: include: Build simulation scenarios and models of various network devices; For different network operations, different network operation models are established, so that each exercise party can respectively use each network operation model to perform network operations on each network device model, wherein the exercise parties include an attacker, a defender, and a third party; Evaluate the network operations of each participant based on the simulated exercise scenario; According to the network operation of each exercise party, each device parameter of each network device model and each scenario parameter of the simulated exercise scenario are changed; the specific steps include: determining the network operation of each exercise party; according to the network operation type of each exercise party, determining the parameters of the network device corresponding to the network operation type of each exercise party; changing the parameters of the network device corresponding to the network operation type of each exercise party to the device parameter state corresponding to the network operation type of each exercise party; according to the device parameter state corresponding to the network operation type of each exercise party, changing each scenario parameter of the simulated exercise scenario; wherein, when the network device model is a data structure with parameters, the network operation is a type of function, and the function is used to call the data structure to change the data in the data structure of the network device model or change the parameters of the network device model; According to the preset training objectives and in combination with the preset constraints, the drill results of the attacker and the defender are dynamically evaluated; wherein the constraints include the ability conditions of the roles participating in the drill, the funding constraints, and the equipment constraints.
7. The method according to claim 6, characterized in that The construction of simulation drill scenarios and various network device models includes: Obtain information about each network device and establish different network device models for different network devices; Setting each device parameter of each of the network device models; A training network is established based on each of the network device models and each device parameter of each of the network device models to form the simulation training scenario.
8. The method according to claim 6, characterized in that The evaluation of the network operations of each exercise party based on the simulated exercise scenario includes: Determine the value score of each network device based on the preset network device scoring criteria; Determine whether each network device is controlled by each exercise party; The scores of the network devices controlled by the attacker and the defender are determined based on the control status of the network devices by the attackers and the value scores of the network devices.
9. A readable storage medium, characterized in that: The readable storage medium stores computer-readable instructions, which, when executed by one or more processors, enable the one or more processors to implement the steps of the network security attack and defense drill method as described in any one of claims 6 to 8.
Citation Information
Patent Citations
Network attack and defense deduction platform based on simulation experiment design
CN112118272A