Power Monitoring Network Security Training Method, Device and System Based on Token Attack

Through the many-to-one cryptographic attack and defense method and discrete Gaussian distribution curve encryption token technology, the problem of single-point attacks being easily discovered in power monitoring network security training is solved, the attack difficulty and defensive challenges are improved, and the security of power monitoring network security training is enhanced.

CN115766210BActive Publication Date: 2025-07-22TECH COLLEGE BRANCH OF STATE GRID CORP OF CHINA +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211422729.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-15
Publication Date
2025-07-22
Estimated Expiration
2042-11-15

AI Technical Summary

Technical Problem

In the existing power monitoring network security training, password attack and defense drills are mostly repeated attacks from a single point to a single point, which is easily discovered by the defense party, and the token technology is easily deciphered, resulting in information and communication security threats.

Method used

Using a many-to-one password attack and defense method, through the encryption token transmission and decryption process, a discrete Gaussian distribution curve is used to encrypt the token, and an encryption token containing random numbers and IP addresses is generated, and an attack password and password are obtained from the attack dictionary for testing login.

Benefits of technology

It increases the difficulty for the defense to detect being attacked, improves the offensive level of password offensive and defense drills, and enhances the technical challenges of the defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766210B_ABST
    Figure CN115766210B_ABST
Patent Text Reader

Abstract

The present invention discloses a power monitoring network security training method, device and system based on token attack. The power monitoring network security training method includes receiving an encrypted token sent by a team leader or team member through a token transmission channel. The token contains and only contains the current number of times the random number of the team leader or team member is called and the IP address of the next team member who obtains this token. Decrypt the received token, and obtain the attack password and password from the attack dictionary according to the decryption result, and perform a trial login on the attack target machine based on the attack password and password. The present invention changes the one-to-one password attack and defense in the prior art into a one-to-many password attack and defense, and the process of multiple people attacking is the same as that of one person attacking, increasing the difficulty for the defense party to detect being attacked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power system security, and particularly relates to a power monitoring network security training method, device and system based on token attack. Background Art

[0002] The power monitoring network is divided into a production area and an information service area. The production area and the information service area are physically isolated by a positive and negative security isolation device. In the production area, it is further divided into Area I and Area II according to the security level, and these two areas are also physically isolated by a positive and negative security isolation device. At the same time, domestic commercial cryptographic algorithms are used to implement two-way identity authentication and data encryption of the communication link, ensuring the security of link communication. It can be seen that the existing power monitoring network security training mostly focuses on improving the security capabilities among members within each area, especially the ability to select password passwords.

[0003] The training of password attack and defense capabilities first needs to improve the capabilities of the attacker. Currently, the means of attacking passwords are mostly repeated single-point-to-single-point attacks, which are easily detected by the defender.

[0004] Token technology is widely used in the current network. For example, when a server performs identity authentication, the server sends an identity authentication token, and this token is also stored in the database. When subsequent requests are sent by the same user, instead of sending the username and password, the authentication token is sent in the request packet, and the validity and authenticity of this token are verified against the token stored in the database. There are also many token-based identity authentications, such as the mechanisms of JSON Web Token (JWT) and OAuth token. However, the existing tokens are just data packets in a certain format and are plaintext information, which are easily deciphered by network attackers, so that the corresponding tokens can be forged to damage information communication. Summary of the Invention

[0005] In view of the above problems, the present invention proposes a power monitoring network security training method, device and system based on token attack, which changes the one-to-one password attack and defense in the prior art into a one-to-many password attack and defense, and the process of multiple people attacking is the same as that of one person attacking, increasing the difficulty for the defender to detect being attacked.

[0006] In order to achieve the above technical objectives and reach the above technical effects, the present invention is realized through the following technical solutions:

[0007] In the first aspect, the present invention provides a power monitoring network security training method based on token attack, including:

[0008] Receiving an encrypted token sent by a team leader or team member through a token transmission channel, where the token contains and only contains the current number of times the random number of the team leader or team member is called and the IP address of the next team member who obtains this token;

[0009] Decrypt the received token, and based on the decryption result, obtain the attack password and the password from the attack dictionary, and attempt to log in to the attack target machine based on the attack password and the password.

[0010] Optionally, the power monitoring network security training method further includes:

[0011] If the attempt to log in fails, then use the value obtained by adding 1 to the current call count of the random number of the team leader or team member as the current call count of its own random number, perform address pairing within the token transmission channel according to the local IP address, find the IP address of the next team member who obtains this token, and then generate an encrypted token and send it to the corresponding team member.

[0012] Optionally, the power monitoring network security training method further includes:

[0013] If the attempt to log in fails, then complete the attack on the attack target machine.

[0014] Optionally, the token transmission channel is a circular queue, including the IP addresses of the team leader and each team member, and the IP addresses are arranged in sequence.

[0015] Optionally, the method for obtaining the attack password and the password includes:

[0016] Decrypt the received token to obtain the current call count of the random number in the token and the IP address of the next team member who obtains this token;

[0017] Compare the local IP address with the IP address of the next team member who obtains this token;

[0018] When the comparison result is that the two are the same, subtract the current call count of its own random number from the current call count of the random number in the token to obtain the number of times R that the rand function needs to be continuously called n ;

[0019] Based on the random number seed, continuously call the rand function R n +1 times to obtain a random number A; the random number seeds of the team leader and each team member are the same;

[0020] Perform a modulo operation on the random number A, take the number of elements in the attack dictionary as the modulus, obtain the index as the attack dictionary, and obtain the attack password and the password from the attack dictionary.

[0021] Optionally, the encrypted token is obtained through the following steps:

[0022] Select the discrete Gaussian distribution parameters μ and σ to construct a discrete Gaussian distribution curve, where μ is the mean and σ is the variance;

[0023] Take each byte of the token in sequence, and use the value of the obtained byte plus the value of the discrete Gaussian distribution parameter σ as the value of the sub-Gaussian random variable, so as to map each byte of the token to a discrete Gaussian random vector, and obtain discrete real points on the discrete Gaussian distribution curve corresponding to each byte;

[0024] Use the storage sequence composed of each discrete real point as the encrypted token.

[0025] Optionally, decrypting the received token includes the following steps:

[0026] Select the discrete Gaussian distribution parameters μ and σ to construct a discrete Gaussian distribution curve;

[0027] Based on the discrete Gaussian distribution curve, obtain the coordinate discrete points on the X-axis corresponding to each discrete real point in the storage sequence, and subtract the discrete Gaussian distribution parameter σ from the coordinate discrete points to restore the current call count of the random number in the token.

[0028] Optionally, σ>150.

[0029] In a second aspect, the present invention provides a power monitoring network security training device based on token attack, including:

[0030] A receiving module, configured to receive the encrypted token sent by the team leader or team member through the token transmission channel, where the token contains and only contains the current call count of the random number of the team leader or team member and the IP address of the next team member who obtains this token;

[0031] An attack module, configured to decrypt the received token, and obtain the attack password and password from the attack dictionary according to the decryption result, and perform a trial login on the attack target machine based on the attack password and password.

[0032] In a third aspect, the present invention provides a power monitoring network security training system based on token attack, including a storage medium and a processor;

[0033] The storage medium is used to store instructions;

[0034] The processor is configured to operate according to the instructions to execute the method according to any one of the first aspects.

[0035] Compared with the prior art, the beneficial effects of the present invention:

[0036] The present invention changes the one-to-one password attack and defense in the prior art into a one-to-many password attack and defense, and the process of multiple people attacking is the same as that of one person attacking, increasing the difficulty for the defense side to detect being attacked. It not only improves the offensive level in the password attack and defense drill, but also poses a technical challenge to the password defense side. Description of the Drawings

[0037] To make the content of the present invention easier to be clearly understood, the following further details the present invention according to specific embodiments in conjunction with the accompanying drawings, where:

[0038] Figure 1 It is a flowchart of a power monitoring network security training method based on token attack according to an embodiment of the present invention. Specific Embodiments

[0039] To make the purpose, technical solution and advantages of the present invention clearer, the following further details the present invention in conjunction with embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the protection scope of the present invention.

[0040] The following describes in detail the application principle of the present invention in conjunction with the accompanying drawings.

[0041] Embodiment 1

[0042] The present invention provides a power monitoring network security training method based on token attack in an embodiment, including the following steps:

[0043] (1) Receive the encrypted token sent by the team leader or team member through the token transmission channel. The token contains and only contains the current call count of the random number of the team leader or team member and the IP address of the next team member to obtain this token.

[0044] (2) Decrypt the received token, and obtain the attack password and password from the attack dictionary according to the decryption result. Try to log in to the attack target machine based on the attack password and password.

[0045] In a specific implementation manner of the embodiment of the present invention, the power monitoring network security training method further includes:

[0046] If the trial login fails, use the value obtained by adding 1 to the current call count of the random number of the team leader or team member as the current call count of its own random number. Perform address pairing within the token transmission channel according to the local machine's IP address to find the IP address of the next team member to obtain this token, and then generate an encrypted token and send it to the corresponding team member.

[0047] If the trial login fails, complete the attack on the attack target machine.

[0048] In a specific implementation manner of the embodiment of the present invention, the token transmission channel is a circular queue, including the IP addresses of the team leader and each team member, and the IP addresses are arranged in order.

[0049] In a specific implementation manner of the embodiment of the present invention, the method for obtaining the attack password and password includes:

[0050] Decrypt the received token to obtain the random number in the token, the current call count, and the IP address of the next team member to obtain this token;

[0051] Compare the local IP address with the IP address of the next team member to obtain this token;

[0052] When the comparison result is that the two are the same, subtract the current call count of the random number in the token from the current call count of the random number in itself to obtain the number of times R that the rand function needs to be continuously called n ;

[0053] Based on the random number seed, continuously call the rand function R n +1 times to obtain the random number A; the random number seeds of the captain and each team member are the same;

[0054] Perform a modulo operation on the random number A, taking the number of attack dictionaries as the modulus, to obtain the index as the attack dictionary, and obtain the attack password and password from the attack dictionary.

[0055] In a specific implementation manner of the embodiment of the present invention, the encrypted token is obtained through the following steps:

[0056] Select the discrete Gaussian distribution parameters μ and σ to construct a discrete Gaussian distribution curve, where μ is the mean and σ is the variance; in the specific implementation process, since the range represented by one byte is 0--255, after taking a value greater than 150, with this value as the center, the minimum on the left is 150 - 125, and the maximum on the right is 150 + 125, which can be distributed within the steepest slope section. Therefore, the σ>150;

[0057] Take each byte of the token in turn, and use the value of the taken byte plus the value of the discrete Gaussian distribution parameter σ as the value of the sub-Gaussian random variable, so as to map each byte of the token to the discrete Gaussian random vector, and obtain the discrete real number points on the discrete Gaussian distribution curve corresponding to each byte;

[0058] Use the storage sequence composed of the discrete real number points as the encrypted token.

[0059] In a specific implementation manner of the embodiment of the present invention, decrypting the received token includes the following steps:

[0060] Select the discrete Gaussian distribution parameters μ and σ to construct a discrete Gaussian distribution curve;

[0061] Based on the discrete Gaussian distribution curve, obtain the coordinate discrete points on the X-axis corresponding to the discrete real number points in the storage sequence, and subtract the discrete Gaussian distribution parameter σ from the coordinate discrete points to restore the current call count of the random number in the token.

[0062] The following describes in detail the power monitoring network security training method based on token attack in the embodiments of the present invention in conjunction with a specific embodiment.

[0063] For the security training of the power monitoring network, first construct the network environments of Zone I, Zone II, and Zone III in the local area network. In Zone I or Zone II, a team is formed to jointly attack a certain node in Zone II or Zone I. The specific attack process is as Figure 1 shown:

[0064] 1. The team leader creates a team

[0065] The team leader first creates a training attack name for this joint attack and subscribes to the message with the attack name as the theme;

[0066] Download materials containing a large number of attack dictionaries from the Internet and store them in the local memory of the team leader first, rather than storing them in a public database to prevent leakage.

[0067] Use the "fixed reference value" as a parameter to call the srand function to complete the setting of the random number seed, and set the current number of calls to the random number to 0.

[0068] 2. Team members join the team

[0069] After the team member program starts, it publishes an online message with the attack name as the theme, and at the same time subscribes to the message with the attack dictionary name as the theme and the message with the "fixed reference value" as the theme.

[0070] Use the "fixed reference value" as a parameter to call the srand function to complete the setting of the random number seed to ensure that the team member and the team leader have the same random number seed, and set the current number of calls to the random number to 0.

[0071] 3. Build a token transmission channel

[0072] Whenever a team member publishes an online message, the team leader obtains the information of the team member going online through subscription and stores the IP address of the team member in the memory pool. When all team members have completed going online, a token transmission channel is generated based on the IP addresses of all team members.

[0073] When all team members have completed going online, the team leader publishes the attack dictionary in the local memory through the message with the attack dictionary name as the theme; and continues to publish the token transmission channel through the message with the token transmission channel as the theme. Team members receive these two pieces of data by subscribing to the message with the attack dictionary name as the theme and the message with the token transmission channel as the theme, and build the same attack dictionary materials and token transmission channel as the team leader in the local memory.

[0074] 4. Token generation process

[0075] The team leader first creates a token through a program. The token contains and only contains the current call count of the random number and the IP address of the next member to obtain this token. The team leader then selects the values of the discrete Gaussian distribution parameters μ and σ (greater than 150) for token encryption and decryption, and publishes them under the topic of "discrete Gaussian distribution parameters". Each team member receives these two parameters under the topic of "discrete Gaussian distribution parameters".

[0076] 5. Token Transmission Process

[0077] 5.1 Token Transmission Sending Process

[0078] First, perform address pairing within the token transmission channel based on the local IP address (from a data structure perspective, the token transmission channel is a circular queue). After finding it, combine the IP address behind it with the current call count of the local random number into an 8-byte string, and then call the token encryption function.

[0079] 5.2 Token Receiving Process

[0080] During the process of the token circulating within the team composed of the team leader and team members, whenever a member receives the token, first call the token decryption function to decrypt the token, obtain the current call count of the sender's random number, and subtract the current call count of its own random number to get the number of times R that the rand function needs to be continuously called. n After continuously calling the rand function R n +1 times, perform a modulo operation on the finally returned random number, taking the number of attack dictionaries as the modulus, to obtain the index of the attack dictionary in the local memory, and retrieve the attack password and password from the attack dictionary. Finally, use the value obtained by adding 1 to the current call count of the sender's random number as the current call count of its own random number.

[0081] In the specific implementation process, the token consists of 8 bytes. The first four bytes store the current call count of the random number, and the last four bytes store the IP address of the next team member to obtain this token;

[0082] The token encryption process can be implemented in the following way:

[0083] Select the center points μ and σ to construct the corresponding discrete Gaussian distribution curve, and take the right half of the distribution (i.e., on the positive axis) of the curve as the mapping curve;

[0084] For each of the 8 bytes of the token in turn, use the value of the byte plus the value of σ as the value of the sub-Gaussian random variable, thereby mapping these 8 bytes to a discrete Gaussian random vector (vector length is 8). Thus, obtain 8 discrete real number points on the discrete Gaussian distribution curve, and send the storage sequence (real number array of 8 elements) composed of these 8 discrete real number points as the encrypted token.

[0085] The token decryption process can be implemented as follows:

[0086] When the receiver receives the encrypted token, it selects the center point μ and σ to construct the corresponding discrete Gaussian distribution curve, and obtains the corresponding discrete coordinate points x on the X-axis from the real number array of these 8 elements (i.e., 8 points on the discrete Gaussian distribution curve). i using x i subtracting the value of σ to restore the original token data of the sender.

[0087] Combined with the curve characteristics of the above discrete Gaussian distribution, when the X-axis takes the value of μ + σ, the slope of the curve nearby is relatively high, which can be well discretized. As a result, the difference between the Y-axis points corresponding to the integer points on the X-axis is relatively large, and the floating-point numbers can be compared using the Y-axis values (for example, if the error is within 0.00000000001, the two floating-point numbers are considered equal), and the corresponding integer points on the X-axis are found. Also, since the object of encryption and decryption is a byte, whose value range is S[0, 255], when σ is greater than 150, the distribution curve of the values within the range S is mapped to the interval [μ + σ - 125, μ + σ + 125].

[0088] 6. Attack process

[0089] Activate the team member who receives the token to make it enter the attack state. The team member decrypts the token and obtains the attack password and the password (i.e., login information), and tries to log in to the attack target machine. If successful, the attack is successful; otherwise, the team member starts the token production process and the token transmission process, and then enters the ready waiting state from the active state by himself.

[0090] Embodiment 2

[0091] Based on the same inventive concept as in Embodiment 1, an electric power monitoring network security training device based on token attack is provided in an embodiment of the present invention, including:

[0092] A receiving module, configured to receive the encrypted token sent by the team leader or team member through the token transmission channel, where the token contains and only contains the number of times the random number of the team leader or team member is currently called and the IP address of the next team member who obtains this token;

[0093] An attack module, configured to decrypt the received token, obtain the attack password and the password from the attack dictionary according to the decryption result, and perform a trial login on the attack target machine based on the attack password and the password.

[0094] The remaining parts are the same as those in Embodiment 1.

[0095] Embodiment 3

[0096] Based on the same inventive concept as in Embodiment 1, an electric power monitoring network security training system based on token attack is provided in an embodiment of the present invention, including a storage medium and a processor;

[0097] The storage medium is used to store instructions;

[0098] The processor is configured to operate according to the instructions to execute the method according to any one of Embodiment 1.

[0099] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only to illustrate the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.

Claims

1. A power monitoring network security training method based on token attack, characterized in that including: Receiving an encrypted token sent by the team leader or team member through the token transmission channel, where the token contains and only contains the current number of invocations of the random number of the team leader or team member and the IP address of the next team member to obtain this token; Activating the team member who receives the token to make it enter the attack state; Decrypting the received token, and obtaining the attack password and password from the attack dictionary according to the decryption result, and performing a trial login to the attack target machine based on the attack password and password; If the trial login is successful, the attack is successful; If the trial login fails, the value obtained by adding 1 to the current number of invocations of the random number of the team member currently performing the trial login is used as the current number of invocations of its own random number. Address pairing is performed within the token transmission channel according to the local machine's IP address to find the IP address of the next team member to obtain this token, and then an encrypted token is generated and sent to the corresponding team member. Then, it enters the ready waiting state from the active state, and activates the team member who receives the token to make it enter the attack state; The method for obtaining the attack password and password includes: Decrypting the received token to obtain the current number of invocations of the random number in the token and the IP address of the next team member to obtain this token; Comparing the local machine's IP address with the IP address of the next team member to obtain this token; When the comparison result shows that the two are the same, subtract the current call count of the random number in the token from the current call count of its own random number to obtain the number of times R that the rand function needs to be continuously called n ; Based on the random number seed, continuously call the rand function R n After calling +1 times, obtain the random number A; the random number seeds of the team leader and each team member are the same; Performing a modulo operation on the random number A, taking the number of elements in the attack dictionary as the modulus, obtaining the index of the attack dictionary, and obtaining the attack password and password from the attack dictionary.

2. The power monitoring network security training method based on token attack according to claim 1, wherein: The token transmission channel is a circular queue, including the IP addresses of the team leader and each team member, and the IP addresses are arranged in order.

3. A power monitoring network security training method based on token attack according to claim 1, characterized in that: The encrypted token is obtained through the following steps: Selecting the discrete Gaussian distribution parameters μ and σ to construct a discrete Gaussian distribution curve, where μ is the mean and σ is the variance; Successively taking each byte of the token, and using the value of the taken byte plus the value of the discrete Gaussian distribution parameter σ as the value of the sub-Gaussian random variable, so as to map each byte of the token to the discrete Gaussian random vector, and obtaining the discrete real number points on the discrete Gaussian distribution curve corresponding to each byte; Taking the storage sequence composed of each discrete real number point as the encrypted token.

4. A power monitoring network security training method based on token attack according to claim 3, characterized in that: Decrypting the received token includes the following steps: Selecting the discrete Gaussian distribution parameters μ and σ to construct a discrete Gaussian distribution curve; Based on the discrete Gaussian distribution curve, obtaining the discrete coordinate points on the X-axis corresponding to each discrete real number point in the storage sequence, and subtracting the discrete Gaussian distribution parameter σ from the coordinate discrete points to restore the current number of invocations of the random number in the token.

5. The power monitoring network security training method based on token attack according to claim 3, wherein: The σ > 150.

6. A power monitoring network security training device based on token attacks, characterized in that, including: A receiving module for receiving an encrypted token sent by the team leader or team member through the token transmission channel, where the token contains and only contains the current number of invocations of the random number of the team leader or team member and the IP address of the next team member to obtain this token; Activating the team member who receives the token to make it enter the attack state; An attack module for decrypting the received token, and obtaining the attack password and password from the attack dictionary according to the decryption result, and performing a trial login to the attack target machine based on the attack password and password; If the trial login is successful, the attack is successful; If the trial login fails, the value obtained by adding 1 to the current call count of the random number of the player currently performing the trial login is used as the current call count of its own random number. The address is paired within the token transmission channel based on the local IP address to find the IP address of the next player to obtain this token. Then, an encrypted token is generated and sent to the corresponding player. Subsequently, it enters the ready waiting state from the active state, activates the player who receives the token, and enables it to enter the attack state; The method for obtaining the attack password and password includes: Decrypt the received token to obtain the current call count of the random number in the token and the IP address of the next player to obtain this token; Compare the local IP address with the IP address of the next player to obtain this token; When the comparison result shows they are the same, subtract the current call count of the random number in the token from the current call count of its own random number to obtain the number of times R that the rand function needs to be continuously called n ; Based on the random number seed, continuously call the rand function R n After calling it +1 times, obtain the random number A; the random number seeds of the team leader and each team member are the same; Perform a modulo operation on the random number A, taking the number of items in the attack dictionary as the modulus, obtain the index as the attack dictionary, and retrieve the attack password and password from the attack dictionary.

7. A power monitoring network security training system based on token attack, characterized in that: It includes a storage medium and a processor; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method according to any one of claims 1-5.