An intent-based software-defined attack behavior orchestration system

By using an intent-based software-defined attack behavior orchestration system, attack resources are decoupled from defense resources, achieving global integration and intelligent orchestration. This solves the problem of attack behavior and resource isolation in existing technologies, and improves the training effect and scalability of attack and defense simulation.

CN115834402BActive Publication Date: 2026-01-02FUJIAN POLYTECHNIC OF INFORMATION TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211292986.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-21
Publication Date
2026-01-02
Estimated Expiration
2042-10-21

AI Technical Summary

Technical Problem

Existing network simulation platforms struggle to isolate attack behaviors and resources in virtual attack and defense scenarios, making it difficult to implement complex, multi-layered, and multi-target APT attacks, thus limiting the improvement of defense capabilities in attack and defense exercises.

Method used

An intent-based software-defined attack behavior orchestration system is adopted. By decoupling attack resources from protection resources through attack resource management, intent management and behavior orchestration modules, attack behaviors are generated and implemented.

Benefits of technology

It reduces the difficulty of implementing complex attack behaviors, improves the training effect and scalability of attack and defense simulation, and provides a larger training space for dynamic attack and defense confrontation exercises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834402B_ABST
    Figure CN115834402B_ABST
Patent Text Reader

Abstract

The application provides an intention-based software-defined attack behavior arrangement system in the technical field of attack-defense virtual simulation, which comprises an attack resource management module, an attack intention management module and an attack behavior arrangement module; the attack resource management module is used for globally integrating attack resources; the attack intention management module is used for translating the identified attack intentions; and the attack behavior arrangement module is used for arranging the attack resources according to the translated attack intentions, so as to generate and implement attack behaviors. The application has the advantages that the training effect and the expansibility of attack-defense simulation are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of attack and defense virtual simulation, and particularly relates to an intent-based software-defined attack behavior orchestration system. BACKGROUND

[0002] With the development of information infrastructure related technologies such as cloud computing, 5G, Internet of Things, and industrial Internet, network space has linked industrial physical systems, human social systems, and network information systems, and has become the cornerstone of the development of social digital economy. The dependence of society on the network promotes the development of network technology on the one hand, and brings many security problems on the other hand. In order to cope with network security and information warfare attacks, various attack and defense simulation training network simulation platforms are put into use to improve various defense capabilities in attack and defense confrontation exercises.

[0003] Attack and defense virtualized network simulation platforms need to apply various virtualization technologies such as node virtualization and link virtualization, and the application of these technologies by cloud platforms has become increasingly mature, so it is a common way to build network simulation platforms based on cloud platforms. However, the virtual attack and defense scenes constructed by the current network simulation platforms are mostly integrated attack and defense, and the attack and defense scenes are isolated from each other, and the attack behaviors and methods constructed are relatively single due to resource constraints, or need to be manually set by users, as shown in the prior art. Figure 3 However, real-world network attacks are not one-time, but multi-level and multi-target, and develop towards complex APT attacks. It is difficult to implement complex attack behaviors in a single attack and defense virtual scene using the existing network simulation platform, and the attack means and resources are often isolated and cannot be shared, which limits the improvement space of defense capabilities in attack and defense confrontation exercises.

[0004] Therefore, how to provide an intent-based software-defined attack behavior orchestration system to improve the training effect of attack and defense simulation and expandability has become a technical problem to be solved. SUMMARY

[0005] The technical problem to be solved by the present application is to provide an intent-based software-defined attack behavior orchestration system to improve the training effect of attack and defense simulation and expandability.

[0006] The present application is implemented as follows: an intent-based software-defined attack behavior orchestration system, comprising an attack resource management module, an attack intent management module, and an attack behavior orchestration module.

[0007] The attack resource management module is configured to globally integrate attack resources, the attack intent management module is configured to translate the identified attack intent, and the attack behavior orchestration module is configured to orchestrate attack resources according to the translated attack intent, and then generate and implement attack behaviors.

[0008] Further, the attack resource management module comprises an attack toolkit management unit, an attack device management unit and an attack classification dataset management unit;

[0009] The attack toolkit management unit is used for setting attack software, attack scripts and attack data sources;

[0010] The attack device management unit is used for adding and deleting management of physical devices and virtual devices;

[0011] The attack classification dataset management unit is used for attack type enumeration and information collection of classification datasets.

[0012] Further, the attack intention management module comprises an attack intention understanding unit and an attack intention translation unit;

[0013] The attack intention understanding unit is used for information extraction of semantic input of a user, and matching attack types in a classification dataset;

[0014] The attack intention translation unit is used for converting an attack intention into an abstract model, and then decomposing into specific attack targets.

[0015] Further, each attack target has a time or logical correlation.

[0016] Further, the attack intention is in a declarative form to describe an ultimate attack effect that a user wants to achieve.

[0017] Further, the attack behavior orchestration module comprises an attack behavior strategy formulation unit, an attack network strategy formulation unit and an attack behavior implementation unit;

[0018] The attack behavior strategy formulation unit is used for formulating an attack behavior strategy comprising an attacked object, attack intensity, attack duration, attack action and attack expectation;

[0019] The attack network strategy formulation unit is used for, when a virtual network between an attack device and an attacked object is created, setting a priority of attack traffic forwarding and available bandwidth according to a network seven-tuple;

[0020] The attack behavior implementation unit is used for creating an attack device, loading an attack toolkit, creating a division attack virtual network, triggering an attack behavior, generating attack traffic, and forwarding an instruction to an SDN virtual switch through a northbound interface of an SDN controller, to complete an attack traffic forwarding operation.

[0021] Further, the attack resource and the protection resource are decoupled.

[0022] The application has the advantages that:

[0023] By decoupling the attack resources from the defense resources in the independent isolated attack and defense virtual scene, that is, separately managing the attack resources as a kind of resource, the attack function of the attack behavior arrangement system is enhanced, so that the user does not need to create attack equipment in a single attack and defense scene when performing attack and defense drills, and the attack behavior setting is started from zero. By integrating the attack resources, the attack behavior arrangement capability based on the attack intention is provided. The user only needs to provide the more abstract attack intention (attack assumption), and the corresponding attack resources and attack behaviors are provided according to the understood attack intention. After the user sets the final attack strategy (attack behavior strategy and attack network strategy), the attack resources are automatically loaded, the attack behavior is triggered to realize the attack intention, the implementation difficulty of the complex attack behavior is effectively reduced, the attack dimension and intensity are improved, and finally the training effect and expansibility of the attack and defense simulation are greatly improved, thereby providing a larger training space for the attack and defense dynamic drill. BRIEF DESCRIPTION OF DRAWINGS

[0024] The application will be further described below with reference to the accompanying drawings and embodiments.

[0025] Figure 1 is a structural schematic diagram of an attack behavior arrangement system based on intention of the application.

[0026] Figure 2 is a networking schematic diagram of an attack and defense virtual scene of the application.

[0027] Figure 3 is a networking schematic diagram of a traditional attack and defense virtual scene. DETAILED DESCRIPTION

[0028] The technical solution in the embodiments of the application has the following general idea: decoupling the attack resources from the defense resources, providing the attack behavior arrangement capability through the global integration of the attack resources, and realizing the intelligent arrangement management of the attack equipment and attack behavior based on the attack intention through the attack intention management module and the attack behavior arrangement module, so as to reduce the implementation difficulty of the complex attack behavior, improve the attack dimension and intensity, and further improve the training effect and expansibility of the attack and defense simulation.

[0029] Please refer to Figures 1 to 3 , a preferred embodiment of an attack behavior arrangement system based on intention of the application, which comprises an attack resource management module, an attack intention management module and an attack behavior arrangement module.

[0030] The attack resource management module is configured to globally integrate attack resources; the attack intention management module is configured to translate the identified attack intention; and the attack behavior arrangement module is configured to arrange attack resources according to the translated attack intention, thereby generating and implementing attack behaviors, i.e., after identifying the attack intention of the user, the attack intention is decomposed into attack targets, more specific attack behavior arrangements are given, and the final attack intention is achieved.

[0031] The attack resource management module includes an attack toolkit management unit, an attack device management unit, and an attack classification dataset management unit.

[0032] The attack toolkit management unit is configured to set attack software, attack scripts, and attack data sources.

[0033] The attack device management unit is configured to add and delete management of physical devices and virtual devices.

[0034] The attack classification dataset management unit is configured to collect information of attack type enumeration and classification datasets, including various common attack types, attack mode descriptions, etc., and can perform add, delete, modify, and query operations, and import external data.

[0035] The attack intention management module includes an attack intention understanding unit and an attack intention translation unit.

[0036] The attack intention understanding unit is configured to extract information from the semantics input by the user and match attack types in the classification dataset.

[0037] The attack intention translation unit is configured to convert the attack intention into an abstract model, such as a yang or json / xml description, and then decompose it into specific attack targets.

[0038] Each attack target has a time or logical association, i.e., a time sequence relationship or a logical cause-and-effect relationship.

[0039] The attack intention is described in a declarative form to describe the final attack effect that the user wants to achieve, without describing the specific implementation of the attack.

[0040] The attack behavior arrangement module includes an attack behavior strategy formulation unit, an attack network strategy formulation unit, and an attack behavior implementation unit.

[0041] The attack behavior strategy formulation unit is configured to formulate attack behavior strategies including attack objects, attack intensity, attack duration, attack actions, and attack expectations; since a single attack target corresponds to a single attack behavior, specific attack behavior strategies need to be formulated for each attack behavior;

[0042] The attacked object is a host, a service or a network; the attack intensity is set according to different types of attacks; the attack action is to launch a specific attack behavior on the attack target by using a specific attack tool, and the default attack action is recommended through attack intention analysis, and the user can also customize the attack action; the attack expectation is the condition for achieving the attack purpose, which is used as the standard for whether the attack is successful or not.

[0043] The attack network policy formulation unit is used to set the priority and available bandwidth of attack traffic forwarding when creating a virtual network between the attack device and the attacked object, so as to guarantee the cooperative work of multiple attack behaviors.

[0044] The attack behavior implementation unit is used to create an attack device, load an attack tool, create and divide an attack virtual network, trigger an attack behavior, generate attack traffic, and forward the instruction to the SDN virtual switch through the northbound interface of the SDN controller to complete the forwarding operation of the attack traffic. That is, the overall network architecture is transformed into an SDN network, all attack sources and attack target devices are connected to the SDN switch, the SDN switch is controlled by the SDN controller, and the network characteristics of the SDN are used to realize the arrangement of the attack network policy.

[0045] The attack resources and the protection resources are decoupled.

[0046] The attack behavior implementation process includes:

[0047] Step one: establish a virtual attack and defense scene and determine the attack target;

[0048] Step two: initialize the data of the attack behavior arrangement system, including the classification data set in the attack resources, and upload the attack tool package;

[0049] Step three: interact with the user through dialogue, navigation and other ways to obtain the attack intention of the user and translate it into an abstract model (attack intention model);

[0050] Step four: initialize the attack behavior strategy according to the abstract model, obtain the attack type and attack behavior strategy through the abstract model, set the attack target and attack parameters;

[0051] Step five: create an attack network policy through the attack behavior arrangement module, set the priority and bandwidth of the attack behavior, and guarantee that the attack traffic can reach the attack target;

[0052] Step six: after setting the attack behavior strategy and the attack network policy, load the attack resources, create a virtual network from the attack device to the attack target, trigger the attack behavior, and monitor whether the attack result reaches the attack expectation.

[0053] In summary, the advantages of the present application are:

[0054] By decoupling the attack resources from the defense resources in the independent isolated attack and defense virtual scene, that is, by separately arranging and managing the attack resources as a kind of resource, the attack function of the attack behavior arrangement system is enhanced, so that the user does not need to create attack equipment in a single attack and defense scene when performing attack and defense drills, and the attack behavior setting is started from zero. By integrating the attack resources, the attack behavior arrangement capability based on the attack intention is provided. The user only needs to provide a more abstract attack intention (attack assumption), and the corresponding attack resources and attack behaviors can be provided according to the understood attack intention. After the user sets the final attack strategy (attack behavior strategy and attack network strategy), the attack resources are automatically loaded, the attack behavior is triggered to realize the attack intention, the implementation difficulty of the complex attack behavior is effectively reduced, the attack dimension and intensity are improved, and finally the training effect and expansibility of the attack and defense simulation are greatly improved. A larger training space is provided for the attack and defense dynamic drill.

[0055] Although the specific embodiments of the present application are described above, those skilled in the art should understand that the specific examples described are only illustrative, and are not intended to limit the scope of the present application. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present application should be covered within the scope of the claims of the present application.

Claims

1. An intent-based software-defined attack behavior orchestration system, characterized in that: It includes an attack resource management module, an attack intent management module, and an attack behavior orchestration module; The attack resource management module is used to globally integrate attack resources; the attack resources are decoupled from the protection resources; the attack intent management module is used to translate the identified attack intent; the attack intent is a declaration describing the final attack effect that the user wants to achieve; the attack behavior orchestration module is used to orchestrate the attack resources according to the translated attack intent, and then generate and implement attack behaviors. The attack resource management module includes an attack toolkit management unit, an attack device management unit, and an attack classification dataset management unit; the attack toolkit management unit is used to set up attack software, attack scripts, and attack data sources. The attack device management unit is used to manage the addition and deletion of physical and virtual devices; the attack classification dataset management unit is used for attack type enumeration and information collection of classification datasets. The attack intent management module includes an attack intent understanding unit and an attack intent translation unit; The attack intent understanding unit is used to extract information from the semantics of the user input and match the attack type in the classification dataset; the attack intent translation unit is used to convert the attack intent into an abstract model, and then decompose it into specific attack targets; each of the attack targets is related in time or logic. The attack behavior orchestration module includes an attack behavior strategy formulation unit, an attack network strategy formulation unit, and an attack behavior implementation unit. The attack behavior strategy formulation unit is used to formulate attack behavior strategies that include the target of attack, attack intensity, attack duration, attack actions, and attack expectations. The attack network strategy formulation unit is used to set the priority and available bandwidth of attack traffic forwarding according to the network seven-tuple when creating a virtual network between the attacking device and the target of attack. The attack execution unit is used to create attack devices, load attack tools, create and partition attack virtual networks, trigger attack behaviors, generate attack traffic, and complete the forwarding operation of attack traffic by calling the northbound interface of the SDN controller to forward instructions to the SDN virtual switch.

Citation Information

Patent Citations

  • Network attack automatic execution / exhibition system and method

    CN101699815A