Test method, device, storage medium and electronic equipment for satellite system security
By constructing a complex kill chain and cyberspace model for satellite systems, targeted threat assessment and simulation are conducted to determine the defense action matrix. This solves the problem of assessing and protecting the cyberspace security of satellite systems and enhances the security and countermeasure capabilities of satellite systems.
Patent Information
- Application Number
- CN202211711971.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2042-12-29
AI Technical Summary
The cyberspace security of satellite systems faces complex attack scenarios and stringent security requirements. The lack of effective security assessment and protection measures makes it difficult to guarantee security under modern and future warfare conditions.
Construct a complex kill chain for the satellite system, conduct targeted threat assessments and threat simulations in cyberspace models, determine the defense action matrix, and enhance the security protection capabilities of the satellite system.
By constructing complex kill chains and cyberspace models based on real-world scenarios, the defense coverage of satellite systems can be improved, their security capabilities enhanced, and a reliable security protection mechanism established to ensure the security of satellite systems under modern and future warfare conditions.
Smart Images

Figure CN116170184B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network attack and defense technology, and in particular to testing methods, apparatus, readable media and electronic devices for satellite system security. Background Technology
[0002] Satellite systems have attracted widespread attention due to their global coverage, low latency, and wide range of industry applications. However, satellite systems are not the same as general information systems. Their cyberspace security not only faces more complex operational scenarios and security conditions, but also has more stringent security levels and protection requirements.
[0003] The security of satellite systems involves extremely diverse and complex issues, with prominent potential vulnerabilities and a wide potential attack surface. Among these are the severe challenges posed by intelligence-level and operational-level attacks from powerful adversaries, as well as the possibility of conventional attacks such as physical strikes, capture, and electromagnetic attacks due to factors such as the supply chain environment, maintenance mechanisms, and data exchange. All of these bring various unpredictable and unavoidable security risks to satellite systems.
[0004] Despite the high level of concern regarding satellite system security, there are currently no effective and feasible means to adequately address its security issues. Several factors contribute to this current state of security, such as the relatively late start of satellite security research, the lack of prioritization of cybersecurity in the design and development of past satellite systems, resulting in numerous legacy vulnerabilities; and the absence of effective methods and corresponding engineering techniques to eliminate cybersecurity risks and vulnerabilities in satellite systems. Furthermore, once satellite system security is breached, attackers can conduct large-scale, high-density, and continuous intelligence gathering activities on their targets, such as radio interception and location tracking, and optical imaging, all of which pose serious security threats.
[0005] Looking at the current and future development of satellite systems, if the cybersecurity issues of satellite systems, especially cyberspace security in actual combat against powerful adversaries, cannot be effectively resolved, it will severely restrict the reliability and operational effectiveness of satellite systems in various operational domains.
[0006] Existing research suffers from several shortcomings: some methods are too complex and have not yet been applied to large-scale equipment systems; existing research focuses on different aspects and lacks a systematic, comprehensive cybersecurity analysis system for satellite system equipment; important satellite system equipment cannot be directly evaluated through penetration testing; and there is a lack of research on threat assessment modeling for scientific and technological equipment. Summary of the Invention
[0007] The embodiments disclosed herein are intended to at least partially address one of the technical problems in the related art, ensuring the security of satellite systems under modern and future warfare conditions.
[0008] Therefore, the first objective of this disclosure is to provide a testing method for satellite system security, comprising:
[0009] A targeted threat assessment was conducted on the complex kill chain of the satellite system, and the threat assessment results were obtained.
[0010] Threat simulations were conducted on the cyberspace model of the satellite system to obtain the results.
[0011] Based on the threat assessment results and the threat simulation results, a defense action matrix is determined.
[0012] In some embodiments, the targeted threat assessment of the composite kill chain of the satellite system and the acquisition of threat assessment results include:
[0013] Construct a composite kill chain based on the aforementioned satellite system;
[0014] A single-point threat assessment is performed on at least one predetermined technical node in the composite kill chain to obtain the threat assessment results.
[0015] In some embodiments, in constructing a composite kill chain based on the satellite system, the composite kill chain includes at least one stage in which the satellite system is located, each stage includes at least one target, each target includes at least one threat technology under at least one threat, and each threat technology forms a predetermined technology node.
[0016] In some embodiments, the threat includes at least physical layer threats, electromagnetic layer threats, and cyberspace layer threats.
[0017] In some embodiments, the threat simulation of the cyberspace model of the satellite system and the acquisition of threat simulation results include:
[0018] A cyberspace model is constructed for the aforementioned satellite system;
[0019] Threat simulations are performed based on the aforementioned cyberspace model to obtain the simulation results.
[0020] In some embodiments, in constructing a cyberspace model for the satellite system, the construction of the cyberspace model includes at least entity construction and relationship construction, and the entity construction includes at least entity subject construction and entity attribute construction.
[0021] In some embodiments, the defense action matrix determined based on the threat assessment results and the threat simulation results includes at least a number of tactical phases, and each tactical phase includes a number of defense actions.
[0022] Another object of this disclosure is to provide a testing apparatus for satellite system security, comprising:
[0023] The first acquisition module is used to perform targeted threat assessment on the complex kill chain of the satellite system and acquire the threat assessment results.
[0024] The second acquisition module is used to perform threat simulation on the cyberspace model of the satellite system and obtain the threat simulation results.
[0025] The determination module is used to determine the defense action matrix based on the threat assessment results and the threat simulation results.
[0026] Another object of this disclosure is to provide a computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the test methods as described above.
[0027] Another object of this disclosure is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements the test method as described above.
[0028] The embodiments disclosed herein construct a composite kill chain based on real-world scenarios, effectively improving the defense coverage of satellite systems. By identifying potential threats to satellite systems, they enhance the security protection of satellite systems, promote the improvement of satellite system security countermeasure capabilities, and form a sound mechanism and mature means that can be universally applied to the simulation and testing of satellite system security protection in our military, thereby ensuring the security of satellite systems under modern and future warfare conditions. Attached Figure Description
[0029] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0030] Figure 1 This is a schematic diagram of the steps of a test method for satellite system security according to an embodiment of the present disclosure;
[0031] Figure 2This is a schematic diagram of the steps of a test method for satellite system security according to an embodiment of the present disclosure;
[0032] Figure 3 This is a schematic diagram of a composite kill chain in a test method for satellite system security according to an embodiment of the present disclosure;
[0033] Figure 4 This is a schematic diagram of a single-point threat assessment in a test method for satellite system security according to an embodiment of this disclosure;
[0034] Figure 5 This is a schematic diagram illustrating the results of a single-point threat assessment in a test method for satellite system security according to an embodiment of this disclosure;
[0035] Figure 6 This is a schematic diagram of the steps of a test method for satellite system security according to an embodiment of the present disclosure;
[0036] Figure 7 This is a schematic diagram of the structure of a satellite system in a test method for satellite system security according to an embodiment of the present disclosure;
[0037] Figure 8 This is a schematic diagram of a cyberspace model of a satellite system in a test method for satellite system security according to an embodiment of the present disclosure;
[0038] Figure 9 This is a schematic diagram of an attack and defense simulation in a test method for satellite system security according to an embodiment of the present disclosure;
[0039] Figure 10 This is a schematic diagram of a defense action matrix in a test method for satellite system security according to an embodiment of the present disclosure. Detailed Implementation
[0040] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.
[0041] The first embodiment of this disclosure provides a testing method for satellite system security. This method can construct a composite kill chain based on real-world conditions, simulating cyber, physical, and electromagnetic attacks that the satellite system may encounter. It enables single-point threat assessment and high-level adversarial simulations under effective enemy scenarios, thereby completing the simulation test of the satellite system's security protection equivalence based on the kill chain. This lays the foundation for improving the credibility of network security assessments and attack / defense technology verification results for the satellite system. Figure 1 As shown, including
[0042] S101, Perform a targeted threat assessment on the complex kill chain of the satellite system and obtain the threat assessment results.
[0043] In this step, a targeted threat assessment is performed on the composite kill chain of the satellite system to obtain the threat assessment results. This step addresses the need for single-point threat assessment within the satellite system. Based on the overall design of the satellite system, it constructs a composite kill chain integrating physical, electromagnetic, and cyberspace threats to achieve macro-level overall design verification of the satellite system and provide support for threat analysis, adversarial simulation, and risk assessment.
[0044] It should be noted that the predetermined technical nodes mentioned here generally refer to specific potentially threatening steps or behaviors within the composite kill chain. This step enables targeted threat assessment and response based on the steps or behaviors included in the predetermined technical nodes of the composite kill chain, thereby forming a list of defense recommendations. This targeted threat assessment and response can be conducted in a semi-automated or human-computer interactive manner, thereby achieving a comprehensive review and verification of the defense capability coverage of potentially threatening technical points.
[0045] Among them, such as Figure 2 As shown, it includes:
[0046] S201, Construct a composite kill chain based on the satellite system.
[0047] In this step, a composite kill chain is constructed based on the satellite system. Given the diverse threats currently faced by the satellite system, and the widespread lack of sufficient understanding of the tactical and technological systems of potential adversaries, making it difficult to predict and simulate their hidden tactical and technological capabilities, this step, to more closely resemble realistic combat scenarios, constructs a simulated composite kill chain based on real-world observations. This chain includes physical threats, electromagnetic threats, and cyberspace threats, describing the actual situation of the satellite system under attack. By constructing this composite kill chain, technical issues such as how an intruder enters the satellite system, how they persist, and how they move laterally can be clarified. This allows for the description of possible actions by the intruder and related factors, providing the necessary simulation data support for subsequent single-point threat assessments and threat simulations. Furthermore, the composite kill chain constructed based on real-world scenarios can effectively improve the satellite system's defense coverage, possessing significant military and scientific value.
[0048] In one specific embodiment, a schematic diagram of the constructed composite kill chain is shown below. Figure 3As shown, the composite kill chain constructed in this step includes at least one stage of the satellite system's lifecycle, with all stages constituting the satellite system's lifecycle. Each stage includes at least one target, and each target includes at least one threat technology under physical, electromagnetic, and cyberspace threats. Each of these threat technologies forms a predetermined technology node. Thus, by constructing a composite kill chain covering the entire lifecycle of the satellite system with potentially threatening technology nodes, an assessment of the satellite system's protection against such complex target scenarios can be achieved.
[0049] S202, Perform a single-point threat assessment on at least one predetermined technical node in the composite kill chain and obtain the threat assessment result.
[0050] After constructing the simulated composite kill chain based on the satellite system through step S201 above, this step involves performing a single-point threat assessment on at least one predetermined technical node in the composite kill chain to obtain the threat assessment results. This single-point threat assessment is a security verification of the overall macroscopic design of the satellite system based on the composite kill chain. Specifically, for the design scheme of the satellite system, threat assessments are performed on each predetermined technical node in the composite kill chain to verify the coverage of its defense capabilities.
[0051] The specific process of single-point threat assessment based on the aforementioned complex kill chain is as follows: Figure 4 As shown, Figure 4 This illustrates a single-point threat assessment process based on the composite kill chain for a specific satellite system, wherein... Figure 4 The left side of the middle section shows the constructed composite kill chain, which includes physical layer threats, electromagnetic layer threats, and cyberspace layer threats. Different threats are mapped to stages-targets-sub-technologies (technical nodes) through a relationship mapping. Figure 4 The right side performs a single-point threat assessment, which assesses the overall macroscopic structure of the satellite system. The assessment methods include targeted assessment and targeted response.
[0052] Figure 5 The assessment results of a single-point threat assessment are shown. For example, different boxes can be used to represent the assessment results of different technical nodes. For example, box ① represents that the satellite system has the ability to defend against the threat technical nodes in the composite kill chain; box ② represents that the satellite system does not have the ability to defend against the threat technical nodes in the composite kill chain, but there are ways to resolve the issue; no box means that the threat technical node is not related to the overall design of the satellite system.
[0053] S102, performs threat simulation on the cyberspace model of the satellite system and obtains the threat simulation results.
[0054] After conducting a targeted threat assessment on at least one predetermined technical node in the composite kill chain of the satellite system through the above step S101 and obtaining the threat assessment results, this step involves performing a simulation of the cyberspace model of the satellite system to obtain the threat simulation results.
[0055] Specifically, addressing the threat assessment needs of the satellite system, this step first requires implementing cyberspace modeling of the satellite system based on a complex interactive network. This involves resolving issues such as the analysis of the satellite system's composition and capabilities, and the determination of inter-node communication and interaction relationships. This allows for the description of security-related factors such as the satellite system's basic information, interaction relationships, threat propagation, and combined effects. Then, threat simulations are performed based on the constructed cyberspace model. By setting up blue-side attack methods and red-side defense methods, as well as intervention and guidance, the threat simulations are assessed. Ultimately, recommendations for adjusting defenses to identify vulnerable points such as the satellite system's exposure surfaces and vulnerabilities are presented as the threat simulation results. Specifically, for example... Figure 6 As shown, it includes:
[0056] S301, Construct a cyberspace model for the satellite system.
[0057] In this step, a cyberspace model is constructed for the satellite system. Specifically, considering that the satellite system is composed of different hardware and software components, information related to network interaction in the satellite system is extracted, and the capabilities required to complete the predetermined tasks are abstracted. At the same time, the relationships between the various subsystems within the satellite system are extracted, and the cyberspace model is constructed based on the abstraction results and relationships.
[0058] Specifically, the construction of the network space model described here can be achieved through two aspects: entity construction and relation construction, as follows:
[0059] On the one hand, the entity construction here mainly includes entity subject construction and entity attribute construction. Entity subject construction is mainly responsible for extracting basic information about the software and hardware of the satellite system. The software and hardware here include at least components, operating systems, applications, protocols, ports, and channels. Entity attribute construction is mainly responsible for abstracting the capabilities of functions and resources required to complete the system objectives or tasks, such as abstracting reconnaissance and detection capabilities, command and control capabilities, etc.
[0060] On the other hand, the relationship construction here mainly abstracts and describes the communication, command and control, and security relationships between the internal systems of the satellite system. These relationships can be directed or undirected, and can be unilateral or multilateral.
[0061] like Figure 7 and Figure 8 As shown, Figure 7 The diagram shows the satellite system, which includes a space system in the air and a ground-based communication earth station subsystem. It may also include a tracking, telemetry and command subsystem and a monitoring and management subsystem. The communication earth station subsystem includes, for example, earth stations and a communication service control center. Figure 8 Based on Figure 7 The model established for the satellite system involves constructing entities for each system and building relationships based on these entities. For example, interactive relationships are established between the space system and the monitoring and management subsystem, and dependency relationships are established between the constructed earth station and the communication service control center. Furthermore, synergistic effect relationships can be built within the communication earth station subsystem. Thus, based on these entity and relationship constructions, a network space model based on the satellite system is ultimately formed.
[0062] S302, based on the cyberspace model, perform threat simulation and obtain the threat simulation results.
[0063] After constructing a cyberspace model for the satellite system through step S301, this step involves performing threat simulations based on the cyberspace model to obtain the simulation results. This threat simulation is a two-way attack and defense simulation based on the cyberspace model of the satellite system, ultimately assessing the network security of the satellite system. Throughout the attack and defense simulation process, deep multi-screen interaction with visual monitoring can be achieved, automatically presenting the overall battlefield situation and attack chain simulation.
[0064] Figure 9 The diagram illustrates a threat simulation process based on the cyberspace model of the satellite system. In the attack and defense simulation, attack technology cards are formed based on the composite kill chain to simulate the attacker submitting an attack link. Defense method cards are formed based on the cyberspace model of the target satellite system. The attacker and defender engage in attack and defense confrontation based on each node in the link. During the attack and defense simulation, the main framework of the composite kill chain in cyberspace and the attack and defense dynamics on the cyberspace model of the satellite system, as well as the director's judgment results, can be observed in real time on a display screen, for example.
[0065] In the implementation of specific attack and defense simulations, the director uses the cyberspace model of the satellite system as a blueprint, selects a pre-research script through the simulation script management module, and initiates a simulation by creating a simulation task. The simulation task status is divided into four stages: not started, preparation period, confrontation period, and summary period. The functions of different roles will be somewhat differentiated in each stage. In an example of a simulation process, the background of the attack and defense simulation is that the blue team uses the target WX system firmware upgrade to implant malicious code into the target WX system. The attack and defense simulation process is as follows:
[0066] Blue Team: Construct a fake WX system firmware upgrade to carry out an attack campaign (initial access - add hardware - firmware upgrade);
[0067] Red Team: Firmware upgrades are only authorized by specific personnel, so this type of attack is ineffective;
[0068] Director's side: Defense successful.
[0069] Blue Team: Target specific firmware upgrade users with watering hole attacks, replacing the firmware files on the official firmware website so that when they access the site, they will find that there is a new firmware that needs to be upgraded;
[0070] Red Team: Hash verification is used for firmware upgrades, which renders this type of attack ineffective;
[0071] Director's side: Defense successful.
[0072] Blue team: Raises questions about Red team's defensive methods;
[0073] Director's side: The blue team can raise their questions;
[0074] Blue Team: In fact, malicious JS code can be used to modify the hash check value displayed on the page, making its content match the hash value of the firmware containing malicious code. Hash collision attacks can also be carried out (initial access - exploiting the trust relationship; initial access - adding hardware - firmware upgrade).
[0075] The director's side: The questioning is valid, but the defense is insufficient. The red team can provide a defense plan.
[0076] Red Team: Digital certificate signature verification is required during firmware upgrade;
[0077] Blue team: Can steal and misuse legitimate digital signatures, enabling firmware containing malicious code to evade detection (defense evasion - damage to trust control - code signing);
[0078] Director's side: Defense failed.
[0079] The final evaluation result is as follows:
[0080] The red team's defense failed, and the problems exposed need to be rectified as soon as possible: for example, using multiple verification methods, including hashes and digital certificates, to verify the source of firmware upgrades.
[0081] By conducting attack and defense simulations based on the aforementioned cyberspace model, and through the setting of attack methods by the blue team, the setting of defense methods by the red team, and the intervention of the director, manual judgment is made, and finally, opinions on the solid defense adjustment of the exposed surface, vulnerable surface and vulnerable points of the satellite system are formed as the threat simulation results.
[0082] S103, Based on the threat assessment results and the threat simulation results, determine the defense action matrix.
[0083] After obtaining the threat assessment results through step S101 and the threat simulation results through step S102, this step determines the defense action matrix based on the threat assessment results and the threat simulation results. Threat assessment identifies deficiencies in the security design of the satellite system and yields threat assessment results; further, threat simulation results are obtained through threat simulation, continuously accumulating a list of defense recommendations, ultimately forming a knowledge system of key defense actions for the privatization of the satellite system.
[0084] Here, various defensive actions are defined in a matrix manner, forming a defensive action matrix, such as... Figure 10 As shown, the defensive action matrix divides each defensive action into tactical stages such as identification, shaping, protection, detection, and response. Each tactical stage includes multiple defensive actions, thereby combining relevant knowledge accumulation to construct a knowledge base for the key defensive action matrix.
[0085] The embodiments disclosed herein construct a composite kill chain based on real-world scenarios, effectively improving the defense coverage of satellite systems. By identifying potential threats to satellite systems, they enhance the security protection of satellite systems, promote the improvement of satellite system security countermeasure capabilities, and form a sound mechanism and mature means that can be universally applied to the simulation and testing of satellite system security protection in our military, thereby ensuring the security of satellite systems under modern and future warfare conditions.
[0086] Based on the same inventive concept as the above embodiments, the second embodiment of this disclosure provides a testing device for satellite system security, including a first acquisition module, a second acquisition module, and a determination module, wherein:
[0087] The first acquisition module is used to perform targeted threat assessment on the composite kill chain of the satellite system and acquire the threat assessment results;
[0088] The second acquisition module is used to perform threat simulation on the cyberspace model of the satellite system and obtain the threat simulation results;
[0089] The determining module is used to determine the defense action matrix based on the threat assessment results and the threat inference results.
[0090] Furthermore, the first acquisition module includes:
[0091] The first building unit is used to build a composite kill chain based on the satellite system;
[0092] The first acquisition unit is used to perform a single-point threat assessment on at least one predetermined technical node in the composite kill chain and acquire the threat assessment result.
[0093] Furthermore, the composite kill chain includes at least one stage in which the satellite system is located, each stage includes at least one target, each target includes at least one threat technology under at least one threat, and each threat technology forms a predetermined technology node.
[0094] Furthermore, the threats include at least physical threats, electromagnetic threats, and cyberspace threats.
[0095] Furthermore, the second acquisition module includes:
[0096] The second construction unit is used to construct a cyberspace model for the satellite system;
[0097] The second acquisition unit is used to perform threat simulation based on the cyberspace model and obtain the threat simulation results.
[0098] Furthermore, the construction of the cyberspace model includes at least entity construction and relationship construction, and the entity construction includes at least entity subject construction and entity attribute construction.
[0099] Furthermore, the defensive action matrix includes at least multiple tactical phases, and each tactical phase includes multiple defensive actions.
[0100] The embodiments disclosed herein construct a composite kill chain based on real-world scenarios, effectively improving the defense coverage of satellite systems. By identifying potential threats to satellite systems, they enhance the security protection of satellite systems, promote the improvement of satellite system security countermeasure capabilities, and form a sound mechanism and mature means that can be universally applied to the simulation and testing of satellite system security protection in our military, thereby ensuring the security of satellite systems under modern and future warfare conditions.
[0101] The third embodiment of this disclosure provides a storage medium, which is a computer-readable medium storing a computer program. When executed by a processor, the computer program implements the method provided in the first embodiment of this disclosure, including the following steps S11 to S13:
[0102] S11, Perform a targeted threat assessment on the complex kill chain of the satellite system and obtain the threat assessment results;
[0103] S12, perform threat simulation on the cyberspace model of the satellite system and obtain the threat simulation results;
[0104] S13, Based on the threat assessment results and the threat simulation results, determine the defense action matrix.
[0105] Furthermore, when the computer program is executed by the processor, it implements other methods provided in the first embodiment of this disclosure.
[0106] The embodiments disclosed herein construct a composite kill chain based on real-world scenarios, effectively improving the defense coverage of satellite systems. By identifying potential threats to satellite systems, they enhance the security protection of satellite systems, promote the improvement of satellite system security countermeasure capabilities, and form a sound mechanism and mature means that can be universally applied to the simulation and testing of satellite system security protection in our military, thereby ensuring the security of satellite systems under modern and future warfare conditions.
[0107] A fourth embodiment of this disclosure provides an electronic device, which includes at least a memory and a processor. The memory stores a computer program, and the processor, when executing the computer program in the memory, implements the method provided in any embodiment of this disclosure. Exemplarily, the computer program steps are as follows: S21 to S23:
[0108] S21, Perform a targeted threat assessment on the complex kill chain of the satellite system and obtain the threat assessment results;
[0109] S22, Perform threat simulation on the cyberspace model of the satellite system and obtain the threat simulation results;
[0110] S23. Based on the threat assessment results and the threat simulation results, determine the defense action matrix.
[0111] Furthermore, the processor also executes the computer program described in the third embodiment above.
[0112] The embodiments disclosed herein construct a composite kill chain based on real-world scenarios, effectively improving the defense coverage of satellite systems. By identifying potential threats to satellite systems, they enhance the security protection of satellite systems, promote the improvement of satellite system security countermeasure capabilities, and form a sound mechanism and mature means that can be universally applied to the simulation and testing of satellite system security protection in our military, thereby ensuring the security of satellite systems under modern and future warfare conditions.
[0113] The aforementioned storage medium may be included in the aforementioned electronic device; or it may exist independently and not be assembled into the electronic device.
[0114] The aforementioned storage medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: acquire at least two Internet Protocol (IP) addresses; send a node evaluation request, including at least two IP addresses, to a node evaluation device, wherein the node evaluation device selects an IP address from the at least two IP addresses and returns it; and receive the IP address returned by the node evaluation device; wherein the acquired IP address indicates an edge node in the content delivery network.
[0115] Alternatively, the storage medium may carry one or more programs that, when executed by the electronic device, cause the electronic device to: receive a node evaluation request including at least two Internet Protocol (IP) addresses; select an IP address from the at least two IP addresses; and return the selected IP address; wherein the received IP address indicates an edge node in the content delivery network.
[0116] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the passenger's computer, partially on the passenger's computer, as a standalone software package, partially on the passenger's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the passenger's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0117] It should be noted that the storage medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any storage medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the storage medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0118] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0119] The units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units are not, in some cases, intended to limit the specific unit.
[0120] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0121] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0122] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0123] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0124] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
[0125] The foregoing has provided a detailed description of several embodiments of this disclosure. However, this disclosure is not limited to these specific embodiments. Those skilled in the art can make various variations and modifications based on the concept of this disclosure, and all such variations and modifications should fall within the scope of protection claimed by this disclosure.
Claims
1. A testing method for satellite system security, characterized in that, include: A targeted threat assessment was conducted on the complex kill chain of the satellite system, and the threat assessment results were obtained. Threat simulations were conducted on the cyberspace model of the satellite system to obtain the results. Based on the threat assessment results and the threat simulation results, a defense action matrix is determined; The targeted threat assessment of the composite kill chain of the satellite system, and the acquisition of threat assessment results, include: Construct a composite kill chain based on the satellite system, wherein the composite kill chain includes at least one stage in which the satellite system is located, all of the stages constitute the life cycle of the satellite system, each stage includes at least one target, each target includes at least one threat technology under at least one threat, each threat technology forms a predetermined technology node, and different threats correspond to stages-targets-sub-technologies through a relationship mapping. A single-point threat assessment is performed on at least one predetermined technical node in the composite kill chain to obtain the threat assessment result; The threats mentioned include at least physical threats, electromagnetic threats, and cyberspace threats.
2. The test method according to claim 1, characterized in that, The threat simulation is performed on the cyberspace model of the satellite system, and the threat simulation results are obtained, including: A cyberspace model is constructed for the aforementioned satellite system; Threat simulations are performed based on the aforementioned cyberspace model to obtain the simulation results.
3. The test method according to claim 2, characterized in that, In constructing the network space model for the satellite system, the construction of the network space model includes at least entity construction and relationship construction, and the entity construction includes at least entity subject construction and entity attribute construction.
4. The test method according to claim 1, characterized in that, The defense action matrix determined based on the threat assessment results and the threat simulation results includes at least multiple tactical phases, and each tactical phase includes multiple defense actions.
5. A testing device for satellite system security, characterized in that, include: The first acquisition module is used to perform targeted threat assessment on the complex kill chain of the satellite system and acquire the threat assessment results. The second acquisition module is used to perform threat simulation on the cyberspace model of the satellite system and obtain the threat simulation results. The determination module is used to determine the defense action matrix based on the threat assessment results and the threat simulation results; The targeted threat assessment of the composite kill chain of the satellite system, and the acquisition of threat assessment results, include: Construct a composite kill chain based on the satellite system, wherein the composite kill chain includes at least one stage in which the satellite system is located, all of the stages constitute the life cycle of the satellite system, each stage includes at least one target, each target includes at least one threat technology under at least one threat, each threat technology forms a predetermined technology node, and different threats correspond to stages-targets-sub-technologies through a relationship mapping. A single-point threat assessment is performed on at least one predetermined technical node in the composite kill chain to obtain the threat assessment result; The threats mentioned include at least physical threats, electromagnetic threats, and cyberspace threats.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the test method as described in any one of claims 1-4.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the test method as described in any one of claims 1-4.
Citation Information
Patent Citations
Network attack stage statistics and prediction method based on Markov chain
CN112769859A
Satellite network safety analysis method, device, system and storage medium
CN113194084A
Simulation modeling method and device for network attack and defense process and network turn war chess
CN113536573A