System testing method, device, equipment and storage medium based on network range
By using preset databases in network shooting range system testing to determine known attack events and orchestrate test technical and tactical chains, the problem that the accuracy of test results depends on the professional knowledge of testers is solved, achieving higher test accuracy and accuracy.
Patent Information
- Application Number
- CN202310184902.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-16
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2043-02-16
AI Technical Summary
The accuracy of test results of existing system testing methods based on network ranges depends on the expertise and skills of attack testers, resulting in low accuracy of assessments.
By obtaining the data to be tested, establishing a preset database, determining known attack events corresponding to the data to be tested, orchestrating the test technical and tactical chain, and obtaining test results based on the security of the chain's test system.
It improves the accuracy of the evaluation of the network shooting range system, ensures that the test technology and tactical chain is closer to actual known attack events, thus ensuring the accuracy of the test.
Smart Images

Figure CN116170225B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network information technology, and in particular, to a system testing method, device, equipment, and storage medium based on a network range. Background Art
[0002] The mainstream method for system testing based on a network range is penetration testing, which includes manual penetration testing and automated penetration testing.
[0003] However, whether it is manual penetration testing or automated penetration testing, the accuracy of the test results of penetration testing on the system of the network range depends to a large extent on the professional knowledge and skills of the attack testers. The test results obtained by different attack testers may be completely different, resulting in low accuracy of the system evaluation of the network range. Summary of the Invention
[0004] In view of this, this application provides a system testing method, device, equipment, and storage medium based on a network range, aiming to improve the accuracy of the system evaluation of the network range.
[0005] To achieve the above object, this application provides a system testing method based on a network range. The system testing method based on a network range includes the following steps:
[0006] Obtain data to be tested;
[0007] Determine known attack events corresponding to the data to be tested from a preset database;
[0008] Arrange test technique and tactic chains according to the known attack events;
[0009] Test the security of the system corresponding to the data to be tested according to the test technique and tactic chains to obtain test results.
[0010] Exemplarily, the known attack events include first known attack events and second known attack events. The step of determining known attack events corresponding to the data to be tested from a preset database includes:
[0011] According to the preset database, determine a first set of APT organizations with an attack initiation frequency greater than a preset frequency, and determine a second set of APT organizations corresponding to the industry of the data to be tested;
[0012] According to the preset database, determine first known attack events applied by the first set of APT organizations and the second set of APT organizations within a preset time range;
[0013] Extract the data features of the data to be tested, and determine the second known attack event corresponding to the data features from the preset database.
[0014] Exemplarily, the step of determining the second known attack event corresponding to the data features from the preset database includes:
[0015] The data features include the type of the system to be tested, the area of the scenario to be tested, the nodes of the scenario to be tested, the access policy of the scenario to be tested, and the vulnerabilities of the scenario to be tested;
[0016] According to any one of the data features, determine the second known attack event corresponding to the data features from the preset database respectively.
[0017] Exemplarily, the step of arranging the test technical and tactical chains according to the known attack events includes:
[0018] Determine the attack technical and tactical chain adopted by the known attack event from the preset database, and determine the attack features of the attack technical and tactical chain;
[0019] Arrange the initial technical and tactical chain for penetration testing according to the attack features;
[0020] Remove the duplicates in the initial technical and tactical chain to obtain the test technical and tactical chain.
[0021] Exemplarily, the step of testing the security of the system corresponding to the data to be tested according to the test technical and tactical chain to obtain the test result includes:
[0022] Extract the technical and tactical features of the test technical and tactical chain;
[0023] Determine the attack tools with a matching degree greater than the preset matching degree with the technical and tactical features from the preset database;
[0024] Initiate a test attack on the system corresponding to the data to be tested according to the technical and tactical features and the attack tools to obtain an attack result;
[0025] Test the security of the system according to the attack result to obtain the test result.
[0026] Exemplarily, the step of testing the security of the system according to the attack result to obtain the test result includes:
[0027] According to the attack result, determine the attack techniques used during the test, and determine the detected attack techniques detected by the system and the blocked attack techniques blocked by the system in the attack techniques;
[0028] Test the security of the system according to the attack techniques, detected attack techniques, and blocked attack techniques to obtain test results.
[0029] Exemplarily, the step of testing the security of the system according to the attack techniques, detected attack techniques, and blocked attack techniques to obtain test results includes:
[0030] Calculate the attack technique coverage rate of the attack techniques in the attack technique set during the current test process according to the attack techniques and the attack technique set within the preset attack technique framework.
[0031] Obtain the weight value corresponding to the attack techniques.
[0032] Calculate the attack technique detection rate and attack technique blocking rate of the system respectively according to the detected attack techniques, blocked attack techniques, and the weight value.
[0033] Test the security of the system according to the attack technique coverage rate, the attack technique detection rate, and the attack technique blocking rate to obtain test results.
[0034] Exemplarily, to achieve the above object, the present application also provides a system testing device based on a network range, and the device includes:
[0035] An acquisition module, configured to acquire data to be tested.
[0036] A determination module, configured to determine known attack events corresponding to the data to be tested from a preset database.
[0037] An orchestration module, configured to orchestrate test use case tactical chains according to the known attack events.
[0038] A test module, configured to test the corresponding system of the data to be tested according to the test use case tactical chains to obtain test results.
[0039] Exemplarily, to achieve the above object, the present application also provides a system testing device based on a network range, and the device includes: a memory, a processor, and a system testing program based on a network range stored on the memory and executable on the processor, and the system testing program based on a network range is configured to implement the steps of the system testing method based on a network range as described above.
[0040] Exemplarily, to achieve the above object, the present application also provides a computer storage medium, and a system testing program based on a network range is stored on the computer storage medium, and when the system testing program based on a network range is executed by a processor, the steps of the system testing method based on a network range as described above are implemented.
[0041] In related technologies, the accuracy of the test results of penetration testing on the system of the network range largely depends on the professional knowledge and skills of the attack testers, resulting in a low accuracy of the system evaluation of the network range. In contrast, in this application, the data to be tested is obtained, and by establishing and using a preset database, the known attack events corresponding to the data to be tested are determined from the preset database. Using the known attack events as a reference, the corresponding test technique and tactic chains are arranged, and based on the test technique and tactic chains, the security of the system corresponding to the data to be tested is tested, thereby obtaining the test results, that is, formulating the corresponding test process to ensure the overall process standardization when testing the system corresponding to the data to be tested. Further, by establishing a preset database, determining the known attack events corresponding to the data to be tested from the preset database, and arranging the corresponding test technique and tactic chains according to the known attack events, the accuracy of the reference data is ensured when testing the system corresponding to the data to be tested, making the test technique and tactic chains closer to the actual known attack events, thereby ensuring the accuracy when using the test technique and tactic chains to test the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 FIG. is a schematic flowchart of the first embodiment of the system testing method based on the network range in this application;
[0043] Figure 2 FIG. is a schematic flowchart of the second embodiment of the system testing method based on the network range in this application;
[0044] Figure 3 FIG. is a schematic flowchart of the third embodiment of the system testing method based on the network range in this application;
[0045] Figure 4 FIG. is a schematic structural diagram of the hardware operating environment involved in the solution of the embodiment of this application.
[0046] The implementation, functional features and advantages of the purpose of this application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0048] This application provides a system testing method based on the network range. Refer to Figure 1 , Figure 1 FIG. is a schematic flowchart of the first embodiment of the system testing method based on the network range in this application.
[0049] An embodiment of the present application provides an embodiment of a system testing method based on a network range. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than here. For the convenience of description, the execution subject is omitted below to describe the steps of the system testing method based on the network range. The system testing method based on the network range includes:
[0050] Step S110: Obtain the data to be tested;
[0051] Exemplarily, the data to be tested is the data provided by the user corresponding to the security test required. The data to be tested mainly includes the object to be tested, the test method, the test time, signing an authorization agreement, etc.
[0052] Among them, a certain type of system provided by the customer (such as an industrial local area network, an education platform network, etc.) is used as the object to be tested;
[0053] Among them, the test method can adopt the method of offensive and defensive exercise testing in the network range. Use attack means to break through the defense system in the system, so as to measure the security performance of the system. In the form of a federal range, connect the system network to which the object to be tested belongs into the network range, and in the network range, this system is used as the defending party, so as to perform attack testing on this system;
[0054] Among them, the test time is determined according to the specific wishes of the customer;
[0055] Among them, signing the authorization agreement is mainly used to obtain the authorization willingness of the customer, limit important data involved in the system of the object to be tested that maintains normal operation, data that is not publicly disclosed for the time being, etc. At the same time, this authorization agreement will include the above-mentioned object to be tested, test method and test time, etc. This agreement is the written agreement between the ordinary customer and the testing party.
[0056] Exemplarily, the data to be tested should include relevant information of the object to be tested. For example, the type of system to be tested, the area of the test scenario, the nodes of the test scenario, the access policy of the test scenario, and the vulnerabilities of the test scenario.
[0057] Among them, the types of systems to be tested include networks or platforms such as industrial local area networks and education platform networks that are put into operation.
[0058] Among them, the area of the test scenario is the actual application scenario of the object to be tested. Taking the local area network and the Internet of Things as examples, the network ranges of the above two are different in size, and there are differences in the communication effects within their networks. The local area network is usually not open to the outside world, while the Internet of Things will adaptively open some permissions.
[0059] Among them, the nodes of the scenario to be tested mainly refer to the situations of each node under the scenarios applied in different systems, including the connections between each node and the overall structure composed of the nodes, etc.
[0060] Among them, the access policy for the scenario to be tested mainly refers to the situation of establishing an access connection between the external network and the network to which the system belongs. Different access policies need to be formulated for the networks of different systems to avoid the direct acquisition of the data inside the system by the external network and the risk of data leakage.
[0061] Among them, the vulnerabilities of the scenario to be tested can be the corresponding vulnerabilities known to the customer and existing in the network to which the system belongs. For example, there is a risk of data being stolen, firewall vulnerabilities, etc.
[0062] The above data can all be obtained through communication with the customer, and the data forms include but are not limited to software data, written data, electronic document data, etc.
[0063] Step S120: Determine the known attack events corresponding to the data to be tested from the preset database;
[0064] The preset database should be a pre-established database or knowledge base containing data related to existing known APT (Advanced Persistent Threat) organizations, attack technique and tactic chains corresponding to attack techniques and tactics, and attack tools, etc.
[0065] Among them, the data related to APT organizations includes but is not limited to the attack activity records or known attack events of APT organizations, the attack targets and adopted attack technique and tactic chains of APT organizations, the industries to which the attack targets of APT organizations belong, the commonly used or typical attack means corresponding to APT organizations, and other relevant data or intelligence on the attacks of APT organizations on certain systems.
[0066] Among them, when establishing the preset database, corresponding special mapping rules can be set. For example, establish a mapping relationship between the known attack events implemented by APT organizations and the corresponding attacked targets and the corresponding characteristics of the attacked targets, establish a mapping relationship between the known attack events implemented by APT organizations and the attack technique and tactic chains they adopt, establish a mapping relationship between the attack technique and tactic chains adopted by APT organizations and the corresponding attack tools, etc. That is, establish corresponding mapping relationships between the known attack events implemented by APT organizations and the data related to them for the subsequent use of the preset database.
[0067] In summary, when the data to be tested is obtained, the known attack events corresponding to the data to be tested can be queried from the preset database.
[0068] Step S130: Compile a test technique and tactic chain according to the known attack events;
[0069] In a preset database, known attack events correspond to data such as corresponding attack techniques and tactics chains. Therefore, according to the known attack events, corresponding data can be referred to from the preset database to arrange corresponding test-use techniques and tactics chains.
[0070] Among them, the test-use techniques and tactics chain is formed by arranging the sequential attack order of different attack tools to form a test-use techniques and tactics chain.
[0071] Exemplarily, the steps of arranging the test-use techniques and tactics chain according to the known attack events include:
[0072] Step a: Determine the attack techniques and tactics chain adopted by the known attack event from the preset database, and determine the attack characteristics of the attack techniques and tactics chain.
[0073] The preset database stores known attack events implemented by APT organizations, as well as the corresponding attack techniques and tactics chains, and conducts actual analysis on the attack techniques and tactics chain to determine its corresponding attack characteristics. Then, according to the attack characteristics, corresponding attack tools are selected and a test-use attack techniques and tactics chain is arranged.
[0074] Step b: Arrange an initial techniques and tactics chain for penetration testing according to the attack characteristics.
[0075] Step c: Remove the duplicates in the initial techniques and tactics chain to obtain the test-use techniques and tactics chain.
[0076] Attack characteristics include the attack content of the attack techniques and tactics chain. For example, the attack order, attack method, attack means, and the attack functions corresponding to the attack method and attack means, etc.
[0077] Exemplarily, in the scenario of offensive and defensive drills in a network range, especially in the scenario of offensive and defensive drills (or offensive and defensive tests) in a federated range, there are many and complex attack tools that the attacking party can choose. For the same attack function, at least one attack tool corresponding to the attack function can be queried. Therefore, when arranging the test-use attack techniques and tactics chain, all available attack tools need to be considered. That is, by determining the attack characteristics of the attack techniques and tactics chain, the available attack tools can be determined, and then the test-use techniques and tactics chain can be arranged according to different permutation and combination effects.
[0078] In addition, when arranging the test technical and tactical chains, the attack technical and tactical chains corresponding to known attack events are directly determined from a preset database. However, there may be cases where the same type of attack technical and tactical chains are used in different known attack events. At the same time, when directly determining the known attack events corresponding to the data to be tested through the preset database, there are known attack events that use the same attack means for different scenarios. At this time, there are duplicate situations when directly arranging the test technical and tactical chains according to the known attack events.
[0079] Therefore, when arranging the technical and tactical chains, first directly arrange the initial technical and tactical chains for penetration testing according to the attack characteristics, and perform deduplication (removing duplicate items) processing on the initial technical and tactical chains to ensure that there are no duplicate items in the test technical and tactical chains used during testing, avoid repeated testing, and thus improve the testing efficiency.
[0080] Step S140: According to the test technical and tactical chains, test the security of the system corresponding to the data to be tested to obtain a test result.
[0081] After arranging the test technical and tactical chains, the test technical and tactical chains can be used to test the system corresponding to the data to be tested, so as to conduct an attack test on the system in the environment of a network range, thereby testing the security functions of the system such as defense, detection, and blocking against external attacks, and then determining the security of the system. Based on this, a test result is obtained.
[0082] That is, the test result is mainly the effect of the security functions adopted by the system when using the test technical and tactical chains to attack the system. At the same time, the selection of the test technical and tactical chains covers data such as known attack events and attack technical and tactical chains corresponding to the data to be tested in the preset database, ensuring the accuracy of testing the system.
[0083] In the related art, the accuracy of the test results of penetration testing on the network range system depends to a great extent on the professional knowledge and skills of the attack testers, resulting in a low accuracy of the system evaluation of the network range. In contrast, in the present application, the data to be tested is obtained, and by establishing and using a preset database, the known attack events corresponding to the data to be tested are determined from the preset database. Using the known attack events as a reference, the corresponding test technique and tactics chain is arranged, and according to the test technique and tactics chain, the security of the system corresponding to the data to be tested is tested, thereby obtaining the test results, that is, formulating the corresponding test process to ensure the overall process standardization when testing the system corresponding to the data to be tested. Further, by establishing a preset database, determining the known attack events corresponding to the data to be tested from the preset database, and arranging the corresponding test technique and tactics chain according to the known attack events, the accuracy of the reference data is ensured when testing the system corresponding to the data to be tested, making the test technique and tactics chain closer to the actual known attack events, thereby ensuring the accuracy when using the test technique and tactics chain to test the system.
[0084] Exemplarily, referring to Figure 2 , Figure 2 FIG. is a schematic flowchart of the second embodiment of the system test method based on the network range in the present application. Based on the first embodiment of the system test method based on the network range in the present application, the second embodiment is proposed. The method further includes:
[0085] Step S210: According to the preset database, determine the first APT organization set with the attack frequency greater than the preset frequency, and determine the second APT organization set corresponding to the industry of the data to be tested;
[0086] When determining the attack events from the preset database, consider the activity of APT organizations and the types of known attack events for screening. For example, the last record of the known attack events implemented by an APT organization was five years ago. An APT organization with long-term inactivity in generating attack activities may no longer generate continuous attacks. Another example is that there are multiple different types of organizations in APT organizations, and they tend to attack different fields and industries. There are differences in the known attack events corresponding to different industry types. At the same time, there are also cases where a certain type of attack means is adopted across multiple industries.
[0087] In summary, when determining the known attack events from the preset database, on the one hand, select the active APT organizations, and on the other hand, select the APT organizations corresponding to the industry of the data to be tested, that is, corresponding to the first APT organization set and the second APT organization set respectively.
[0088] Among them, a first set of APT organizations whose attack frequencies initiated by the APT organizations are greater than a preset frequency. This attack frequency refers to the number of attacks launched by the APT organization in recent years (taking two years, three years, or five years as an example), and the preset frequency is a threshold set according to the attack frequencies of most APT organizations, so as to screen out APT organizations with higher attack frequencies and obtain the first set of APT organizations.
[0089] Among them, for different industries of APT organizations, to ensure the accuracy of testing, in addition to determining a part of the active first set of APT organizations, it is also necessary to further determine a second set of APT organizations corresponding to the industry of the data to be tested. When determining the second set of APT organizations, their activity levels (judgment of attack frequencies) do not need to be considered.
[0090] Step S220: According to the preset database, determine the first known attack events applied by the first set of APT organizations and the second set of APT organizations within a preset time range;
[0091] After screening out the APT organization sets that meet the requirements, the known attack events corresponding to the first set of APT organizations and the second set of APT organizations can be determined from the preset database. At the same time, the time when the known attack events occur needs to be limited, that is, the known attack events are launched by APT organizations within a preset time range, so as to ensure the accuracy when using the first known attack events as a reference to arrange test technical and tactical chains. For example, with the continuous development of network security, if APT organizations only use attack methods from many years ago, they will be easily intercepted and blocked. The attack methods adopted by APT organizations will also develop accordingly. Therefore, limiting the corresponding launch time of the first known attack events helps to improve the accuracy during testing.
[0092] Step S230: Extract the data features of the data to be tested, and determine the second known attack events corresponding to the data features from the preset database.
[0093] The data features of the data to be tested include the type of the system to be tested, the area of the scene to be tested, the nodes of the scene to be tested, the access policy of the scene to be tested, and the vulnerabilities of the scene to be tested.
[0094] Based on the features included in the above data features, using the data features as matching items, perform corresponding matching from the preset database, so as to obtain the second known attack events corresponding to the data features.
[0095] Exemplarily, the step of determining the second known attack events corresponding to the data features from the preset database includes:
[0096] Step d: According to any one of the data features, respectively determine the second known attack events corresponding to the data features from the preset database.
[0097] When determining the second known attack events corresponding to the data features from the preset database according to the data features, the above features are respectively used as items to be matched and matched with the data in the preset database, so that according to any data feature, a group of corresponding second known attack events can be matched. Thus, according to the data features, five groups of corresponding second known attack events can be matched from the preset database, avoiding the situation where the feature data is directly mixed as a matching item, resulting in a small number and a narrow scope of the second known attack events obtained.
[0098] In this embodiment, according to the preset database, determine the first APT organization set with the attack frequency greater than the preset frequency, and determine the second APT organization set corresponding to the industry of the data to be tested; according to the preset database, determine the first known attack events applied by the first APT organization set and the second APT organization set within the preset time range; extract the data features of the data to be tested, and determine the second known attack events corresponding to the data features from the preset database, that is, respectively determine the corresponding first APT organization set and second APT organization set according to the attack frequency and the industry corresponding to the data to be tested, ensure that the scope involved in the selected APT organization set corresponds to the data to be tested, ensure the accuracy of the first known attack events, and determine the second known attack events according to the data features, ensure the second known attack events, and use the overall content of the first known attack events and the second known attack events as the reference content during testing to ensure a wide range involved during testing and ensure the accuracy during testing.
[0099] Exemplarily, refer to Figure 3 , Figure 3 is the flowchart of the third embodiment of the system testing method based on the network range of the present application. Based on the first and second embodiments of the system testing method based on the network range of the present application, the third embodiment is proposed. The method further includes:
[0100] Step S310: Extract the technique-tactic features of the test technique-tactic chain;
[0101] The test technical and tactical chain is arranged corresponding to the attack technical and tactical chain. There are certain differences between the attack characteristics of the test technical and tactical chain and the attack characteristics corresponding to the attack technical and tactical chain of the attack event. That is, the arrangement effect achieved through the arrangement method is the same as the attack effect corresponding to the attack event, but there may be distinctions in attack characteristics. Therefore, the technical and tactical characteristics of the test technical and tactical chain are only the attack characteristics of the corresponding techniques and tactics of the test technical and tactical chain, which include the attack order, attack tendency, attack means, attack process, etc. The attack effect that the technical and tactical characteristics can satisfy should be the same as the attack effect satisfied by the attack characteristics, but the characteristic content that the technical and tactical characteristics can include is greater than or equal to the characteristics included in the attack characteristics.
[0102] Step S320: Determine the attack tools in the preset database that have a matching degree greater than the preset matching degree with the technical and tactical characteristics.
[0103] According to the technical and tactical characteristics, the corresponding attack tools can be determined from the preset database. However, the attack content included in the technical and tactical characteristics may be relatively complex, and there are corresponding differences between the attack characteristics that the attack tools can achieve and the technical and tactical characteristics. Moreover, to ensure the test accuracy, the characteristics in the technical and tactical characteristics should be adaptable for replacement, that is, to increase the range of available attack tools. When selecting attack tools, the selection requirements can be adaptively reduced. That is, by setting the preset matching degree to 80%, all attack tools with an 80% matching similarity with the technical and tactical characteristics are classified as available attack tools.
[0104] Step S330: Initiate a test attack on the system corresponding to the data to be tested according to the technical and tactical characteristics and the attack tools, and obtain an attack result.
[0105] According to the technical and tactical characteristics and the attack tools, the attack process of the test technical and tactical chain can be implemented. At this time, according to the technical and tactical characteristics, use the attack tools to initiate a test attack on the system corresponding to the data to be tested, so as to obtain an attack result. The attack result includes achieving the attack purpose and not achieving the attack purpose. The situation of achieving the attack purpose can be further divided into the attack process being detected but the system being unable to respond and the attack process not being detected but the system being unable to respond. In addition, the situation of not achieving the attack purpose is that the attack process is detected and the system makes a response, blocking the attack or successfully defending.
[0106] Step S340: Test the security of the system according to the attack result and obtain a test result.
[0107] According to the attack result, the test process of the security of the system can be completed, and thus a test result can be obtained. The test result mainly includes the test result after attacking the system, which is divided into the defense result or the result of being attacked and broken by the system under different attack situations.
[0108] Meanwhile, a corresponding test report is output according to the test results. The content of the report can be customized according to the customer's needs. For example, according to the test results, list the vulnerabilities in the system that are easily breached, or evaluate the situation where the system successfully defends, list the existing defense advantages of the system, and other such report contents.
[0109] Exemplarily, the step of testing the security of the system according to the attack results to obtain the test results includes:
[0110] Step e: According to the attack results, determine the attack techniques used in the test process, and determine the detected attack techniques detected by the system in the attack techniques, and the blocked attack techniques blocked by the system;
[0111] Step f: According to the attack techniques, the detected attack techniques and the blocked attack techniques, test the security of the system to obtain the test results.
[0112] In the process of completing the integrity test of the system according to the attack results to obtain the test results, it mainly depends on the corresponding data in the attack results, including the attack techniques used in the test process, and in the test process, the detected attack techniques successfully detected by the system and the blocked attack techniques successfully blocked by the system, that is, count the attack techniques successfully detected by the system and the attack techniques successfully blocked by the system, so as to determine the detection effect of the system against external attacks and the blocking effect against external attacks.
[0113] Exemplarily, the step of testing the security of the system according to the attack techniques, the detected attack techniques and the blocked attack techniques to obtain the test results includes:
[0114] Step g: According to the attack techniques and the set of attack techniques within the preset attack technique framework, calculate the attack technique coverage rate of the attack techniques in the set of attack techniques during the current test process;
[0115] Step h: Obtain the weight value corresponding to the attack technique;
[0116] Step i: According to the detected attack techniques, the blocked attack techniques and the weight value, calculate the attack technique detection rate and the attack technique blocking rate of the system respectively;
[0117] Step j: According to the attack technique coverage rate, the attack technique detection rate and the attack technique blocking rate, test the security of the system to obtain the test results.
[0118] The above-mentioned specific method for evaluating the system's detection effect on external attacks and the blocking effect on external attacks can be used to formulate a corresponding evaluation calculation formula.
[0119] The evaluation calculation formula includes attack technology coverage, attack technology detection rate and attack technology blocking rate.
[0120] The attack technology coverage rate is calculated as follows: attack technology coverage rate = (the sum of the number of attack technologies used in the attack / the sum of all attack technologies in the preset attack technology framework) × 100%. The preset attack technology framework is an attack technology framework that is unanimously recognized by relevant personnel and includes all currently known attack technologies.
[0121] The calculation formula of the attack technology detection rate is: attack technology detection rate = (the sum of the detected attack technology weights ÷ the total attack technology weights) × 100%.
[0122] The calculation formula of the attack technology blocking rate is: attack technology blocking rate = (the sum of blocked attack technology weights ÷ the total attack technology weights) × 100%.
[0123] When calculating the attack technology detection rate and the attack technology blocking rate, it is necessary to calculate based on the weight value corresponding to each attack technology. The weight value of the attack technology is the weight value pre-allocated to all attack technologies within the attack technology framework. The specific allocation depends on the usage frequency corresponding to each attack technology. The higher the usage frequency, the greater the weight value.
[0124] The sum of the attack technology weights used in calculating the attack technology detection rate and the attack technology blocking rate is the sum of the weight values corresponding to the attack technologies used during the test.
[0125] The sum of the weights of the detected attack technologies is the sum of the weights corresponding to the attack technologies successfully detected by the system during the test.
[0126] The sum of the weights of blocked attack technologies is the sum of the weights corresponding to the attack technologies successfully blocked by the system during the test.
[0127] In this embodiment, the tactical features of the test tactical chain are extracted; the attack tools with a matching degree greater than the preset matching degree with the tactical features are determined from the preset database; according to the tactical features and the attack tools, a test attack is launched against the system corresponding to the data to be tested, and an attack result is obtained; according to the attack result, the security of the system is tested to obtain a test result, that is, the corresponding system of the data to be tested is attacked and tested through the attack tools corresponding to the test tactical chain, so as to complete the entire test process, and further, according to the detection and blocking of the attack technology by the system in the test process, corresponding criteria for evaluating the security of the system are formulated, and corresponding calculation formulas for evaluation are formulated, so as to ensure the clarity of the test results of the system and give them to the customer in an intuitive data form, thereby improving the comfort of the customer when reading the test results.
[0128] In addition, the present application also provides a system testing device based on a network range, and the system testing device based on a network range includes:
[0129] An acquisition module, configured to acquire data to be tested;
[0130] A determination module, configured to determine known attack events corresponding to the data to be tested from a preset database;
[0131] An orchestration module, configured to orchestrate a test tactical chain according to the known attack events;
[0132] A test module, configured to test the corresponding system of the data to be tested according to the test tactical chain to obtain a test result.
[0133] Exemplarily, the determination module includes:
[0134] A first determination sub-module, configured to determine a first APT organization set with an attack frequency greater than a preset frequency according to the preset database, and determine a second APT organization set corresponding to the industry of the data to be tested;
[0135] A second determination sub-module, configured to determine first known attack events applied by the first APT organization set and the second APT organization set within a preset time range according to the preset database;
[0136] A first extraction sub-module, configured to extract the data features of the data to be tested, and determine second known attack events corresponding to the data features from the preset database.
[0137] Exemplarily, the extraction sub-module includes:
[0138] The first determination unit is configured to respectively determine, according to any one of the data features, a second known attack event corresponding to the data feature from a preset database.
[0139] Exemplarily, the orchestration module includes:
[0140] A third determination sub-module, configured to determine an attack technique and tactic chain adopted by the known attack event from the preset database, and determine an attack feature of the attack technique and tactic chain;
[0141] An orchestration sub-module, configured to orchestrate an initial technique and tactic chain for penetration testing according to the attack feature;
[0142] A removal sub-module, configured to remove duplicate items in the initial technique and tactic chain to obtain a test technique and tactic chain.
[0143] Exemplarily, the test module includes:
[0144] A second extraction sub-module, configured to extract technique and tactic features of the test technique and tactic chain;
[0145] A matching sub-module, configured to determine an attack tool whose matching degree with the technique and tactic feature is greater than a preset matching degree from the preset database;
[0146] A test sub-module, configured to initiate a test attack on the system corresponding to the data to be tested according to the technique and tactic feature and the attack tool, and obtain an attack result;
[0147] A test sub-module, configured to test the security of the system according to the attack result, and obtain a test result.
[0148] Exemplarily, the test sub-module includes:
[0149] A second determination unit, configured to determine an attack technique used in the test process according to the attack result, and determine a detected attack technique detected by the system and a blocked attack technique blocked by the system in the attack technique;
[0150] A test unit, configured to test the security of the system according to the attack technique, the detected attack technique and the blocked attack technique, and obtain a test result.
[0151] Exemplarily, the test unit includes:
[0152] A first calculation sub-unit, configured to calculate an attack technique coverage rate of the attack technique in the attack technique set in the current test process according to the attack technique and the attack technique set within a preset attack technique framework;
[0153] An acquisition subunit, configured to acquire the weight value corresponding to the attack technique;
[0154] A second calculation subunit, configured to calculate the attack technique detection rate and the attack technique blocking rate of the system respectively according to the detected attack techniques, the blocked attack techniques and the weight value;
[0155] A test subunit, configured to test the security of the system according to the attack technique coverage rate, the attack technique detection rate and the attack technique blocking rate, and obtain a test result.
[0156] The specific implementation manner of the system test device based on the network range in this application is basically the same as each embodiment of the above-mentioned system test method based on the network range, and will not be elaborated here.
[0157] In addition, this application also provides a system test device based on the network range. As Figure 4 shown, Figure 4 is a schematic structural diagram of the hardware operating environment involved in the solution of the embodiment of this application.
[0158] Exemplarily, Figure 4 can be the schematic structural diagram of the hardware operating environment of the system test device based on the network range.
[0159] As Figure 4 shown, the system test device based on the network range may include a processor 401, a communication interface 402, a memory 403 and a communication bus 404. Among them, the processor 401, the communication interface 402 and the memory 403 complete mutual communication through the communication bus 404. The memory 403 is used to store a computer program; the processor 401 is configured to implement the steps of the system test method based on the network range when executing the program stored on the memory 403.
[0160] The communication bus 404 mentioned in the above system test device based on the network range may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus 404 can be divided into an address bus, a data bus and a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0161] The communication interface 402 is used for communication between the system test device based on the network range and other devices.
[0162] The memory 403 may include a Random Access Memory (RAM), or may also include a Non-Volatile Memory (NM), such as at least one disk memory. Optionally, the memory 403 may also be at least one storage device located far from the aforementioned processor 401.
[0163] The aforementioned processor 401 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0164] The specific implementation manner of the system test device based on the network range in this application is basically the same as each embodiment of the above-mentioned system test method based on the network range, and will not be elaborated here.
[0165] In addition, an embodiment of this application also proposes a computer storage medium, on which a system test program based on the network range is stored. When the system test program based on the network range is executed by a processor, the steps of the system test method based on the network range as described above are implemented.
[0166] The specific implementation manner of the computer storage medium of this application is basically the same as each embodiment of the above-mentioned system test method based on the network range, and will not be elaborated here.
[0167] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or system. Without further limitations, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article, or system including that element.
[0168] The serial numbers of the embodiments of this application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0169] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present application.
[0170] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. A system testing method based on a network range, characterized in that, the system testing method based on a network range includes the following steps: Obtain data to be tested; Determine known attack events corresponding to the data to be tested from a preset database; Arrange test technical and tactical chains according to the known attack events; Extract the technical and tactical features of the test technical and tactical chains, wherein the feature content included in the technical and tactical features is greater than or equal to the features included in the attack features corresponding to the attack events; Determine attack tools with a matching degree greater than a preset matching degree with the technical and tactical features from the preset database, wherein the attack tools are obtained by reducing the selection requirements; Initiate a test attack on the system corresponding to the data to be tested according to the technical and tactical features and the attack tools, and obtain an attack result; Test the security of the system according to the attack result to obtain a test result.
2. The system testing method based on a network range according to claim 1, characterized in that, the known attack events include a first known attack event and a second known attack event, and the step of determining known attack events corresponding to the data to be tested from a preset database includes: According to the preset database, determine a first APT organization set with an attack frequency greater than a preset frequency, and determine a second APT organization set corresponding to the industry of the data to be tested; According to the preset database, determine the first known attack events applied by the first APT organization set and the second APT organization set within a preset time range; Extract the data features of the data to be tested, and determine second known attack events corresponding to the data features from the preset database.
3. The system testing method based on a network range according to claim 2, characterized in that, the step of determining second known attack events corresponding to the data features from the preset database includes: The data features include the type of system to be tested, the area of the test scenario, the nodes of the test scenario, the access policy of the test scenario, and the vulnerabilities of the test scenario; According to any one of the data features, respectively determine second known attack events corresponding to the data features from the preset database.
4. The system testing method based on a network range according to claim 1, characterized in that, the step of arranging test technical and tactical chains according to the known attack events includes: Determine the attack technical and tactical chains adopted by the known attack events from the preset database, and determine the attack features of the attack technical and tactical chains; Arrange an initial technical and tactical chain for penetration testing according to the attack features; Remove the duplicates in the initial technical and tactical chain to obtain a test technical and tactical chain.
5. The system testing method based on a network range according to claim 1, characterized in that, the step of testing the security of the system according to the attack result to obtain a test result includes: Based on the attack results, determine the attack techniques used during the test, and determine the detected attack techniques detected by the system among the attack techniques, as well as the blocked attack techniques blocked by the system; Based on the attack techniques, detected attack techniques, and blocked attack techniques, test the security of the system to obtain a test result.
6. The system testing method based on a network range as claimed in claim 5, characterized in that the step of testing the security of the system based on the attack techniques, detected attack techniques, and blocked attack techniques to obtain a test result includes: Calculating the attack technique coverage rate of the attack techniques in the attack technique set during the current test process according to the attack techniques and the attack technique set within the preset attack technique framework; Obtaining the weight value corresponding to the attack technique; Calculating the attack technique detection rate and attack technique block rate of the system respectively according to the detected attack techniques, blocked attack techniques, and the weight value; Testing the security of the system based on the attack technique coverage rate, the attack technique detection rate, and the attack technique block rate to obtain a test result.
7. A system testing device based on a network range, characterized in that the system testing device based on a network range includes: An acquisition module, configured to acquire data to be tested; A determination module, configured to determine a known attack event corresponding to the data to be tested from a preset database; An orchestration module, configured to orchestrate a test technique and tactic chain according to the known attack event; A second extraction sub-module, configured to extract the technique and tactic features of the test technique and tactic chain, where the feature content included in the technique and tactic features is greater than or equal to the features included in the attack features corresponding to the attack event; A matching sub-module, configured to determine an attack tool with a matching degree greater than a preset matching degree with the technique and tactic features from the preset database, where the attack tool is obtained by relaxing the selection requirements; A test sub-module, configured to initiate a test attack on the system corresponding to the data to be tested according to the technique and tactic features and the attack tool to obtain an attack result; A test sub-module, configured to test the security of the system according to the attack result to obtain a test result.
8. A system testing device based on a network range, characterized in that the device includes: a memory, a processor, and a system testing program based on a network range stored on the memory and executable on the processor, and the system testing program based on a network range is configured to implement the steps of the system testing method based on a network range as described in any one of claims 1 to 6.
9. A computer storage medium, characterized in that a system testing program based on a network range is stored on the computer storage medium, and when the system testing program based on a network range is executed by a processor, it implements the steps of the system testing method based on a network range as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method, system and equipment for testing defensive performance of service system and medium
CN114611110A