A method, device and system for building a network security experiment system
By combining a mobile edge computing platform with a cybersecurity test range, the problems of high server load and slow data processing speed in existing technologies are solved, realizing a flexible cybersecurity experimental environment that supports 5G standard protocols and experimental verification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-20
- Publication Date
- 2026-04-14
AI Technical Summary
Existing cybersecurity test ranges suffer from excessive server load and slow data processing speed in experimental environments. Furthermore, experimental data is limited by the public network environment, making effective verification and simulation impossible.
By combining a mobile edge computing platform with a cybersecurity test range, adopting an open distributed platform that supports multiple interfaces and customized functions, and combining 5G standard protocols, a cybersecurity experimental system can be built.
It alleviated the server load, improved the calculation speed of experimental data, supported secondary development and verification, and achieved the flexibility and realism of the experimental environment, thus meeting the needs of scientific research.
Smart Images

Figure CN115714668B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network data security technology, and in particular to a method, apparatus and system for building a network security experimental system. Background Technology
[0002] my country attaches great importance to the development of cybersecurity capabilities. Against this backdrop, local departments, research institutes and universities have stepped up their efforts to develop research related to cyber range security, and have made improvements and breakthroughs in areas such as large-scale network simulation, attack behavior simulation, virtual-real integration, and cybersecurity talent training.
[0003] However, existing test range technologies are not yet mature, and test range deployment is based on the public network environment of operators, which has certain limitations. In scientific research environments, for experimental scenarios such as network security protocol verification, new technology verification, and network attack and defense, the high security requirements of the public network environment restrict the experimental environment. At the same time, the large amount of data generated by the experiment puts too much pressure on the server's computing capacity, and the processing speed of the large amount of experimental data is slow. Summary of the Invention
[0004] (a) Technical problems to be solved
[0005] In view of the above-mentioned shortcomings and deficiencies of the prior art, the present invention provides a method, apparatus and system for building a network security experimental system, which solves the technical problem of slow processing speed for large amounts of data in the prior art.
[0006] (II) Technical Solution
[0007] To achieve the above objectives, the main technical solutions adopted by the present invention include:
[0008] In a first aspect, embodiments of the present invention provide a method for building a network security experimental system. The method includes: obtaining first construction parameters for a network security test range built for a target area; wherein the frequency band used by the network security test range is a different frequency band from the frequency band used by the network operator, and the first construction parameters include a first UPF network element in the network security test range; obtaining second construction parameters for a mobile edge computing platform built for the target area; wherein the second construction parameters include a second UPF network element in the edge computing platform; and merging and building the network security test range and the mobile edge computing platform based on the first UPF network element and the second UPF network element to obtain a network security experimental system.
[0009] Therefore, this application combines a mobile edge computing platform with a network security test range. The mobile edge computing platform is characterized by being an open, distributed platform, while the core network of the network security test range can be deployed to support multiple open interfaces, customized interfaces, and function additions. This supports the addition and experimental verification of the developed technologies in the system and can be used to support secondary development, 5G standard protocols, and process research. By combining the two, the problems of excessive server load and slow processing speed of large amounts of experimental data in existing technologies can be solved.
[0010] Optionally, the frequency band used in the cybersecurity test range is 3.3GHz-3.4GHz.
[0011] Optionally, the cybersecurity test range includes a 5G base station and a first UPF network element communicating with the 5G base station; the construction process of the cybersecurity test range includes: acquiring environmental data of the target area; wherein, the environmental data includes building data related to buildings in the target area; determining the installation parameters of the 5G base station based on the building data; determining the first setting parameters of the first UPF network element based on the installation parameters of the 5G base station; selecting the frequency band used by the cybersecurity test range; and constructing the cybersecurity test range based on the installation parameters, the first setting parameters, and the frequency band used by the cybersecurity test range.
[0012] Optionally, the first setup parameters also include AMF network elements; the setup process of the mobile edge computing platform further includes: privately deploying AMF network elements so that packet capture and analysis can be performed on data packets in the AMF network elements.
[0013] Optionally, the first setup parameters also include SMF network elements; the setup process of the mobile edge computing platform further includes: privately deploying SMF network elements so that packet capture and analysis can be performed on data packets in the SMF network elements.
[0014] Optionally, the mobile edge computing platform includes an algorithm server and a second UPF network element that is communicatively connected to the algorithm server and the first UPF network element respectively; the construction process of the mobile edge computing platform includes: acquiring business data and business traffic data of the target area; determining the selection parameters of the algorithm server and the second setting parameters of the second UPF network element and the network architecture of the mobile edge computing platform based on the business data and business traffic data; and building the mobile edge computing platform based on the selection parameters of the algorithm server and the second setting parameters of the second UPF network element and the network architecture.
[0015] Optionally, the network security experimental system also includes at least one distributed test range; the construction process of the mobile edge computing platform further includes: connecting each of the at least one distributed test range to a second UPF network element for communication.
[0016] Optionally, the process of building a mobile edge computing platform further includes: setting up risk points for the mobile edge computing platform; setting up services for the mobile edge computing platform; and setting up network elements for the mobile edge computing platform.
[0017] Secondly, embodiments of this application provide an apparatus for building a network security experimental system. The apparatus includes: a first acquisition module, used to acquire first construction parameters of a network security test range built for a target area; wherein the frequency band used by the network security test range is a different frequency band from the frequency band used by the network operator, and the first construction parameters include a first UPF network element in the network security test range; a second acquisition module, used to acquire second construction parameters of a mobile edge computing platform built for the target area; wherein the second construction parameters include a second UPF network element in the edge computing platform; and a fusion construction module, used to fuse the network security test range and the mobile edge computing platform based on the first UPF network element and the second UPF network element to obtain a network security experimental system.
[0018] Thirdly, embodiments of this application provide a network security experimental system, which can be built using any of the methods for building a network security experimental system described in the first aspect.
[0019] To make the above-mentioned objectives, features and advantages to be achieved by the embodiments of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 A schematic diagram of a network security experimental system provided in an embodiment of this application is shown;
[0022] Figure 2 A flowchart illustrating a method for building a network security experimental system according to an embodiment of this application is shown;
[0023] Figure 3 This paper illustrates a network architecture diagram of a network security experimental system provided in an embodiment of this application.
[0024] Figure 4 A schematic diagram of an apparatus for building a network security experimental system is shown in an embodiment of this application. Detailed Implementation
[0025] To better explain and facilitate understanding of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0026] Currently, in addition to the problems of excessive server load and slow processing speed of large amounts of experimental data, existing technologies also have the problem of being unable to obtain underlying real data and signaling logs due to the lack of open interfaces.
[0027] Based on this, this application provides a solution for building a network security experimental system. By combining 5G Mobile Edge Computing (MEC) technology with an open 5G test range, and considering that 5G MEC is characterized by an open distributed platform, the 5G test range core network deployment supports multiple open interfaces, customized interfaces, and function additions to support the addition and experimental verification of the developed technologies in the system. It can be used to support secondary development, 5G standard protocols, and process research. By combining the two, the problems of excessive server load and slow data processing speed in existing technologies can be solved.
[0028] To better understand the above technical solutions, exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that the present invention can be understood more clearly and thoroughly, and that the scope of the present invention can be fully conveyed to those skilled in the art.
[0029] Please see Figure 1 , Figure 1 A schematic diagram of a network security experimental system provided in an embodiment of this application is shown. Figure 1 As shown, the cybersecurity experimental system may include multiple distributed test ranges, a cybersecurity test range, a mobile edge computing platform, and experimental hosts for conducting cybersecurity experiments. Each of the distributed test ranges includes Customer Premises Equipment (CPE) and host equipment from non-target areas. For example, if the target area is a first campus area, the host equipment in each of the distributed test ranges may be related host equipment from other campuses, thus accessing the mobile edge computing platform via the corresponding CPE. The cybersecurity test range may include a 5G base station and a first UPF network element; the mobile edge computing platform may include a second UPF network element, an MEC server, and an algorithm server.
[0030] Specifically, the 5G base station can communicate with the second UPF network element through the first UPF network element, and the second UPF network element can communicate with the MEC server. The MEC server can also communicate with the CPE in each distributed test range through the second UPF network element, and the MEC server can also communicate with the algorithm server, and the algorithm server can also communicate with the experimental host.
[0031] Furthermore, this application allows MEC to be deployed in important aggregation data centers to form an MEC resource pool, and User Plane Function (UPF) and Mobile Edge Computing Platform (MEP) can be deployed simultaneously on the MEC virtual platform. The UPF can provide service offloading capabilities according to offloading strategies, and the MEP performs services such as route distribution, application registration management, and vFW. Additionally, the test range network environment can adopt an independently built 5G private network, employing an open-interface and data center (DC) isolated core network, a self-built base station with dedicated frequency bands for the wireless network, and a VPN-isolated bearer network to construct a 5G dedicated network conforming to 3GPP standards. Service experiment data will not leave the target area. The test range's experimental private network (i.e., the network specifically constructed for experiments in this application) is completely isolated end-to-end from the public network (i.e., the operator network in the target area). A virtual-physical combined 5G security test range is constructed using a self-owned independent frequency band to simulate a real 5G network environment, enabling attack and defense experiments, verification of new 5G algorithms and technologies, and talent training.
[0032] It should be understood that the above-described network security experimental system is merely exemplary, and those skilled in the art can make various modifications based on the above method, and the modified solutions also fall within the protection scope of this application.
[0033] Please see Figure 2 , Figure 2 A flowchart illustrating a method for building a network security experimental system according to an embodiment of this application is shown. Figure 2 As shown, the method includes:
[0034] Step S210: Obtain the first setup parameters for the cybersecurity test range built for the target area. The frequency band used by the cybersecurity test range is different from the frequency band used by the network operator. The first setup parameters include the first UPF network element in the cybersecurity test range.
[0035] It should be understood that the specific region of the target area can be set according to actual needs, and the embodiments of this application are not limited thereto.
[0036] For example, the target region can be the region where a specific institution is located.
[0037] It should also be understood that the parameters included in the first setup parameters can be set according to actual needs, and the embodiments of this application are not limited thereto.
[0038] For example, the first setup parameters include the installation parameters of the first UPF network element and the 5G base station.
[0039] It should also be understood that the specific frequency band used in the cybersecurity test range can be set according to actual needs, and the embodiments of this application are not limited thereto.
[0040] For example, to ensure open interface capabilities, wireless base station deployments differ from the capabilities of public network frequency bands used by operators. Therefore, network security test ranges use the 3.3GHz-3.4GHz frequency band.
[0041] To facilitate understanding of the process of building a cybersecurity test range, the following description uses specific examples.
[0042] Specifically, the first step is to understand the environment of the target area to obtain environmental data. This environmental data may include building data and signal transmission environment in the target area, and building data may include the specific number of buildings, the spacing between buildings, and the height of buildings.
[0043] Furthermore, the installation parameters for 5G base stations can be determined based on building data. These parameters can include the number of 5G base stations, their installation locations, and specific equipment models. For example, if the target area is determined to have five buildings based on building data, one 5G base station can be set up for each building. The installation location and specific equipment model of the corresponding 5G base station can be determined based on factors such as building height and spacing, ensuring that each 5G base station can cover its corresponding building.
[0044] Furthermore, the first setting parameters of the first UPF network element can be determined based on the installation parameters of the 5G base station. These first setting parameters may include interface parameters, etc.
[0045] Furthermore, the frequency band used by the cybersecurity range can be selected. For example, a dedicated frequency band can be applied for for the cybersecurity range, and this frequency band is different from the frequency band used by network operators.
[0046] Therefore, based on the above data, construction routes can be planned, and can be followed... Figure 1 The communication connections shown are used for communication, thereby building a network security test range.
[0047] In other words, a cybersecurity test range includes the necessary network environment construction, signal surveying, site selection, equipment selection, and determination of construction routes.
[0048] Step S220: Obtain the second setup parameters for the mobile edge computing platform built for the target area. The second setup parameters include the second UPF network element in the edge computing platform.
[0049] It should be understood that the parameters included in the second setup parameters can be set according to actual needs, and the embodiments of this application are not limited thereto.
[0050] For example, the second setup parameters include network topology relationships and second UPF network elements.
[0051] To facilitate understanding of the construction process of a mobile edge computing platform, specific embodiments are described below.
[0052] Specifically, firstly, business data and traffic data required for the target area can be obtained. For example, business may include network security protocol verification, new technology verification, and network attack and defense. Secondly, based on the business data and traffic data, the required computing capacity (e.g., processing efficiency and concurrency) of the MEC server can be determined, and the device parameters of the MEC server can be determined based on this required computing capacity. These device parameters may include device type and memory size. Thirdly, the MEC server can be selected based on its device parameters. Finally, the second setting parameters of the second UPF network element can also be determined based on the business data and traffic data.
[0053] Correspondingly, the device parameters of the algorithm server can also be determined based on business data and its business traffic data. For details, please refer to the selection process of the MEC server, which will not be repeated here.
[0054] Furthermore, it also allows for the configuration of interactions between network elements in the mobile edge computing platform and network elements in the network security test range.
[0055] Optionally, please see Figure 3 , Figure 3 A schematic diagram of the network architecture of a network security experimental system provided in an embodiment of this application is shown. Figure 3As shown, the network architecture includes a Baseband Unit (BBU), a Remote Radio Unit (RRU), a first UPF network element, a Distributed Unit (DU), a Centralized Unit (CU), a second UPF network element, a Data Network (DN), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), Unified Data Management (UDM), a Network Repository Function (NRF), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), and an Access and Mobility Management Function (AUSF). Among these, the BBU, RRU, first UPF network element, DN, DU, CU, NSSF, NEF, UDM, NRF, AMF, SMF, and AAUSF can all be network elements found in a network security testbed; the second UPF network element can be a network element found in a mobile edge computing platform.
[0056] In addition, AMF network elements can be deployed privately, which enables packet capture and analysis of data packets (e.g., signaling) in AMF network elements.
[0057] For example, the signaling is sent to the AMF through the CU and DU, thus realizing the signaling to the core network element of the test range. Then the signaling is processed into the session, and the session needs to be distributed to the second UPF network element. Then the second UPF network element processes the signaling and returns it to the base station.
[0058] Correspondingly, SMF network elements can also be deployed privately, thereby enabling packet capture and analysis of data packets (e.g., signaling) within the SMF network elements.
[0059] Furthermore, it also allows configuration of the interactions between services within the mobile edge computing platform, i.e., configuration of the services that the mobile edge computing platform can handle.
[0060] Furthermore, the network architecture of the mobile edge computing platform can be configured. For example, the MEC server and the algorithm server can be connected, and each of the at least one distributed test range can be communicatively connected to a second UPF network element.
[0061] Furthermore, risk points for the mobile edge computing platform can be configured. For example, these risk points can include infrastructure layer security risk points, network element functional layer security risk points, and data layer security risk points. Infrastructure layer security risk points include network security risk points, SDN security risk points, and trusted computing risk points; network element functional layer security risk points include network element management plane risk points, network element control plane risk points, and network element forwarding plane risk points.
[0062] Furthermore, the experimental data traffic of the mobile edge computing platform can be configured. For example, an upper limit can be set for the experimental data traffic of the mobile edge computing platform.
[0063] Furthermore, it allows for the definition of use cases for the mobile edge computing platform. For example, use cases could include the verification of new technologies and algorithms.
[0064] Therefore, a mobile edge computing platform can be built based on the above settings.
[0065] Step S230: Based on the first UPF network element and the second UPF network element, the network security test range and the mobile edge computing platform are integrated and built to obtain the network security experimental system.
[0066] Specifically, the first UPF network element and the second UPF network element can be connected to communicate, thereby enabling the integrated construction of a network security test range and a mobile edge computing platform.
[0067] For example, the topological relationship, service interaction and risk points between the first UPF network element and the second UPF network element can be deployed, and the deployment method can be to select the same local area network range on the network side of the core network server equipment and the edge computing server equipment, and preset the interface protocol for transmitting experimental data to realize user plane local processing.
[0068] Therefore, this application serves two purposes: firstly, it satisfies the testing and verification of key technologies in 5G test ranges, supporting research and verification of 5G communication protocols, 5G security attack and defense technologies, and 5G flexible networking architectures. This necessitates the construction of a flexible and open 5G network test range that conforms to industry standards. Secondly, it meets the testing and verification needs of 5G industry applications, supporting the verification of new application technologies under 5G network coverage. These primarily include high-speed application services, low-latency application services, and large-scale coverage application services, such as remote driving, telemedicine, VR, IoT terminal data, and edge computing. This requires the construction of an industry-standard 5G network that integrates the edge, network, and cloud, ultimately forming a comprehensive open experimental network supporting the edge, network, and cloud.
[0069] Furthermore, this application deploys 5GMEC computing and storage capabilities closer to users, providing network support for users' mobile needs through the physical dense deployment of servers. At the same time, real-time computing capabilities are deployed at the network edge to provide low-latency guarantees for massive mobile terminal devices and large amounts of experimental data, alleviating the network pressure of high bandwidth for attack and defense drills, experimental verifications, etc.
[0070] Furthermore, while existing network test ranges have played a corresponding role in supporting attack and defense exercises, testing and verification, and technology incubation, they still need to be improved and supplemented in terms of network environment and processing speed. This application proposes to take 5G test ranges as the main body, utilize 5G edge computing test range technology and 5G channels to collect real-time multi-source scientific research data, such as verification data and core operation data. Through the low latency processing capability of MEC edge computing, the core experimental data can be collected, analyzed, processed and displayed in real time.
[0071] Furthermore, the construction of 5G network range data processing centers is highly centralized and large-scale, making data privacy protection for edge devices a critical concern. Data security concerns arise because sensitive raw sensor data and computation results are often not transmitted to other physical devices. Additionally, as the primary contact point for data infrastructure, 5GMEC edge computing devices can enforce privacy policies applied by data owners before data is uploaded, enhancing data security.
[0072] It should be understood that the above-described method for building a network security experimental system is merely exemplary, and those skilled in the art can make various modifications based on the above method, and the modified solutions also fall within the protection scope of this application.
[0073] Please see Figure 4 , Figure 4 A schematic diagram of an apparatus 400 for building a network security experimental system, according to an embodiment of this application, is shown. Figure 4 As shown, the device 400 includes:
[0074] The first acquisition module 410 is used to acquire the first setup parameters of the network security range built for the target area; wherein the frequency band used by the network security range is a different frequency band from the frequency band used by the network operator, and the first setup parameters include the first UPF network element in the network security range;
[0075] The second acquisition module 420 is used to acquire the second construction parameters of the mobile edge computing platform built for the target area; wherein, the second construction parameters include the second UPF network element in the edge computing platform;
[0076] The fusion construction module 430 is used to integrate and build a network security test range and a mobile edge computing platform based on the first UPF network element and the second UPF network element to obtain a network security experimental system.
[0077] Since the apparatus described in the above embodiments of the present invention is an apparatus used to implement the methods of the above embodiments of the present invention, those skilled in the art can understand the specific structure and modifications of the system / apparatus based on the methods described in the above embodiments of the present invention, and therefore will not be repeated here. All apparatuses used in the methods of the above embodiments of the present invention fall within the scope of protection of the present invention.
[0078] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0079] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions.
[0080] It should be noted that any reference numerals placed between parentheses in the claims should not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claims. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The invention can be implemented by means of hardware comprising several different components and by means of a suitably programmed computer. In claims that enumerate several means, several of these means may be embodied by the same hardware. The use of the terms first, second, third, etc., is merely for convenience of expression and does not indicate any order. These terms can be understood as part of the component names.
[0081] Furthermore, it should be noted that in the description of this specification, the terms "one embodiment," "some embodiments," "embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0082] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the claims should be interpreted to include both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0083] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, then this invention should also include these modifications and variations.
Claims
1. A method for building a network security experimental system, characterized in that, include: Obtain the first setup parameters for a cybersecurity test range built for a target area; wherein the frequency band used by the cybersecurity test range is a different frequency band from the frequency band used by the network operator, and the first setup parameters include the first UPF network element in the cybersecurity test range; Obtain the second setup parameters for the mobile edge computing platform built for the target region; wherein, the second setup parameters include the second UPF network element in the edge computing platform; Based on the first UPF network element and the second UPF network element, the network security test range and the mobile edge computing platform are integrated and built to obtain the network security experimental system. The cybersecurity test range includes a 5G base station and a first UPF network element that is communicatively connected to the 5G base station; the construction process of the cybersecurity test range includes: Obtain environmental data for the target area; wherein, the environmental data includes building data related to buildings in the target area; Based on the building data, the installation parameters of the 5G base station are determined; Based on the installation parameters of the 5G base station, the first setting parameters of the first UPF network element are determined; Select the frequency band used by the network security test range; The network security range is constructed based on the installation parameters, the first setting parameters, and the frequency band used by the network security range. The mobile edge computing platform includes an algorithm server and a second UPF network element that is communicatively connected to both the algorithm server and the first UPF network element; the construction process of the mobile edge computing platform includes: Obtain business data and business traffic data for the target region; Based on the business data and the business traffic data, the selection parameters of the algorithm server, the second setting parameters of the second UPF network element, and the network architecture of the mobile edge computing platform are determined respectively. The mobile edge computing platform is built based on the selection parameters of the algorithm server, the second setting parameters of the second UPF network element, and the network architecture. By establishing a communication connection between the first UPF network element and the second UPF network element, the integrated construction of the network security test range and the mobile edge computing platform can be achieved.
2. The method according to claim 1, characterized in that, The network security test range uses the frequency band of 3.3GHz-3.4GHz.
3. The method according to claim 2, characterized in that, The first setup parameters also include AMF network elements; the setup process of the mobile edge computing platform further includes: The AMF network element is deployed in a private manner so that packet capture and analysis can be performed on the data packets in the AMF network element.
4. The method according to claim 2, characterized in that, The first setup parameters also include SMF network elements; the setup process of the mobile edge computing platform further includes: The SMF network element is deployed in a private manner so that packet capture and analysis can be performed on the data packets in the SMF network element.
5. The method according to claim 1, characterized in that, The network security experimental system also includes at least one distributed test range; the construction process of the mobile edge computing platform further includes: Each of the at least one dispersed target ranges is communicatively connected to the second UPF network element.
6. The method according to claim 1, characterized in that, The process of building the mobile edge computing platform further includes: Identify the risk points of the mobile edge computing platform; Configure the services of the mobile edge computing platform; and, Configure the network elements of the mobile edge computing platform.
7. An apparatus for building a network security experimental system, characterized in that, include: The first acquisition module is used to acquire the first setup parameters of the network security test range built for the target area; wherein the frequency band used by the network security test range is a different frequency band from the frequency band used by the network operator, and the first setup parameters include the first UPF network element in the network security test range; The second acquisition module is used to acquire the second construction parameters of the mobile edge computing platform built for the target area; wherein, the second construction parameters include the second UPF network element in the edge computing platform; The fusion construction module is used to fuse and build the network security test range and the mobile edge computing platform based on the first UPF network element and the second UPF network element to obtain the network security experimental system; The cybersecurity test range includes a 5G base station and a first UPF network element communicatively connected to the 5G base station; the device also includes: The network security test range construction module is used to: acquire environmental data of the target area; wherein the environmental data includes building data related to buildings in the target area; determine the installation parameters of the 5G base station based on the building data; determine the first setting parameters of the first UPF network element based on the installation parameters of the 5G base station; select the frequency band used by the network security test range; and construct the network security test range based on the installation parameters, the first setting parameters, and the frequency band used by the network security test range. The mobile edge computing platform includes an algorithm server and a second UPF network element that is communicatively connected to the algorithm server and the first UPF network element, respectively; the device further includes: The mobile edge computing platform construction module is used to: acquire business data and business traffic data of the target area; determine the selection parameters of the algorithm server, the second setting parameters of the second UPF network element, and the network architecture of the mobile edge computing platform based on the business data and the business traffic data; and construct the mobile edge computing platform based on the selection parameters of the algorithm server, the second setting parameters of the second UPF network element, and the network architecture. The fusion construction module is specifically used to: establish a communication connection between the first UPF network element and the second UPF network element, thereby enabling the fusion construction of the network security test range and the mobile edge computing platform.
8. A network security experimental system, characterized in that, The network security experimental system is constructed using the method for constructing a network security experimental system as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Large-scale network target range and construction method, construction device and construction equipment thereof
CN113438103A
Shooting range target system
US9360283B1