An attack-defense confrontation test method, device, medium and equipment
By obtaining the initial strategies of the security tools and attack tools under test, and using an attack-defense mapping table to calculate attack and defense capability values, the problem of inaccurate assessment of defense capabilities in existing technologies is solved, thus achieving accuracy in adversarial testing.
Patent Information
- Application Number
- CN202211666418.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2042-12-23
AI Technical Summary
Existing defense capability testing methods cannot accurately determine the defense effectiveness of the security tool under test, resulting in the inability to obtain a true assessment of defense capabilities.
By obtaining the initial defense strategy of the security tool under test and the initial attack strategy of the attack tool, an effective defense strategy is obtained using an attack-defense mapping table, attack and defense capability values are calculated, and adversarial information is generated to determine the defense effect.
It enables the assessment of the defense capabilities of security tools under test in actual use and accurately judges their adversarial test results.
Smart Images

Figure CN116318799B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, and in particular to a method and device for attack-defense confrontation testing, a medium and equipment. BACKGROUND
[0002] With the development of network technology, various attack tools and defense tools are constantly updated. In order to better evaluate the defense capability of the defense system, it is necessary to clearly understand the defense capability of each security tool in the defense chain against various attack methods. The existing test method for defense capability is to perform actual confrontation testing of the to-be-tested security tool and the corresponding attack strategy to obtain the corresponding result. However, there are also cases where the to-be-tested security tool or attack tool that needs to be tested cannot be obtained, thereby making it impossible to obtain the real defense capability through actual confrontation testing. Further, the defense capability of the to-be-tested security tool in actual use cannot be obtained, resulting in the inability to accurately judge the defense effect of the to-be-tested security tool. SUMMARY
[0003] In view of the above technical problem that the defense effect of the to-be-tested security tool cannot be accurately judged, the technical solution adopted by the present application is as follows:
[0004] According to one aspect of the present application, a method for attack-defense confrontation testing is provided, the method comprising the following steps:
[0005] Obtaining at least one initial defense strategy corresponding to the to-be-tested security tool and at least one initial attack strategy corresponding to the to-be-tested attack tool.
[0006] According to the attack-defense mapping table, obtaining an effective defense strategy corresponding to each initial attack strategy. The effective defense strategy is an initial defense strategy that has defense capability against the corresponding initial attack strategy. The attack-defense mapping table is used to record the correspondence between each initial attack strategy and initial defense strategy.
[0007] Conducting confrontation processing on each initial attack strategy and the corresponding effective defense strategy to generate test information corresponding to each initial attack strategy.
[0008] According to the test information, generating confrontation information of the to-be-tested security tool and the to-be-tested attack tool.
[0009] The confrontation processing includes:
[0010] Obtaining an attack capability value of the initial attack strategy.
[0011] Obtaining a defense capability value of each corresponding effective defense strategy.
[0012] According to the attack capability value and the corresponding defense capability value, generating test information corresponding to each initial attack strategy.
[0013] In the present application, further, the attack capability value of the initial attack strategy is acquired, comprising:
[0014] An attack mapping table is acquired. The attack mapping table is used for recording the corresponding relationship between each initial attack strategy and attack capability value.
[0015] According to the attack mapping table, the attack capability value corresponding to the initial attack strategy is acquired.
[0016] In the present application, further, the attack mapping table is obtained through the following steps:
[0017] The attack capability conversion processing is performed on each initial attack strategy, and the attack capability value corresponding to each initial attack strategy is generated.
[0018] According to the corresponding relationship between each initial attack strategy and attack capability value, the attack mapping table is generated.
[0019] The attack capability conversion processing comprises:
[0020] According to the damage level, the brand-new level and the concealment level corresponding to the initial attack strategy, the attack capability value of the initial attack strategy is generated.
[0021] In the present application, further, the defense capability value of each effective defense strategy corresponding thereto is acquired, comprising:
[0022] The defense tool category to which the security tool to be tested belongs is determined.
[0023] A defense mapping table is acquired. The defense mapping table is used for recording the corresponding relationship between each defense tool category and basic defense capability value.
[0024] According to the defense mapping table and the defense tool category to which the security tool to be tested belongs, the basic defense capability value corresponding to the security tool to be tested is generated.
[0025] According to the basic defense capability value and the brand-new degree of each effective defense strategy corresponding to the security tool to be tested, the defense capability value of each effective defense strategy is generated.
[0026] In the present application, further, the defense mapping table is obtained through the following steps:
[0027] A plurality of evaluation security tools corresponding to each defense tool category are acquired.
[0028] The defense capability conversion processing is performed on the plurality of evaluation security tools, and the basic defense capability value corresponding to each defense tool category is generated.
[0029] According to the basic defense capability value corresponding to each defense tool category, the defense mapping table is generated.
[0030] The defense capability conversion processing comprises:
[0031] According to the equipment technique and tactic coverage and the attack performance of each evaluation security tool, a sub-defense capability value corresponding to each evaluation security tool is generated.
[0032] According to the plurality of sub-defense capability values, a defense capability value of the defense tool category is generated.
[0033] In the present application, further, the effective defense strategies are multiple.
[0034] According to the attack capability value and the corresponding defense capability value, test information corresponding to each initial attack strategy is generated, including:
[0035] According to the defense capability values corresponding to the plurality of effective defense strategies, a total defense capability value is generated.
[0036] According to the attack capability value and the corresponding total defense capability value, test information corresponding to each initial attack strategy is generated.
[0037] In the present application, further, the defense capability value includes a plurality of types of sub-defense capability values.
[0038] The sub-defense capability value is obtained through the following steps:
[0039] An assignment weight corresponding to the sub-defense capability value is obtained.
[0040] According to the assignment weight and the defense capability value, the sub-defense capability value is generated.
[0041] According to a second aspect of the present application, an attack-defense confrontation test device is provided, comprising:
[0042] A first obtaining module is configured to obtain at least one initial defense strategy corresponding to a to-be-tested security tool and at least one initial attack strategy corresponding to a to-be-tested attack tool.
[0043] A second obtaining module is configured to obtain, according to an attack-defense mapping table, an effective defense strategy corresponding to each initial attack strategy. The effective defense strategy is an initial defense strategy that has a defense capability for the corresponding initial attack strategy. The attack-defense mapping table is used to record the corresponding relationship between each initial attack strategy and initial defense strategy.
[0044] An confrontation processing module is configured to perform confrontation processing on each initial attack strategy and the corresponding effective defense strategy, to generate test information corresponding to each initial attack strategy.
[0045] A generating module is configured to generate, according to the test information, confrontation information of the to-be-tested security tool and the to-be-tested attack tool.
[0046] The confrontation processing includes:
[0047] An attack capability value of the initial attack strategy is obtained.
[0048] obtaining a defense capability value corresponding to each effective defense strategy.
[0049] generating test information corresponding to each initial attack strategy according to the attack capability value and the corresponding defense capability value.
[0050] According to a third aspect of the present application, a non-transitory computer readable storage medium is provided, which stores a computer program, and the computer program, when executed by a processor, implements the attack-defense confrontation test method.
[0051] According to a fourth aspect of the present application, an electronic device is provided, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor, when executing the computer program, implements the attack-defense confrontation test method.
[0052] The present application has at least the following beneficial effects:
[0053] In the present application, at least one initial defense strategy corresponding to a to-be-tested security tool to be subjected to confrontation test and at least one initial attack strategy corresponding to a to-be-tested attack tool are obtained, so as to solve the problem that the to-be-tested security tool or attack tool to be subjected to test cannot be obtained. Then, an effective defense strategy corresponding to each initial attack strategy is obtained through an attack-defense mapping table. Then, an attack capability value corresponding to each initial attack strategy and a defense capability value of the corresponding effective defense strategy are calculated through confrontation test. Then, the defense effect of the to-be-tested security tool on each initial attack strategy is determined more accurately by comparing the attack capability value and the corresponding defense capability value. BRIEF DESCRIPTION OF DRAWINGS
[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.
[0055] Figure 1 A flow chart of an attack-defense confrontation test method provided by an embodiment of the present application.
[0056] Figure 2 A structural block diagram of an attack-defense confrontation test device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0057] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.
[0058] According to an aspect of the present application, as shown in Figure 1 a method for attack-defense confrontation test is provided, and the method comprises the following steps:
[0059] S100: Obtain at least one initial defense strategy corresponding to a to-be-tested security tool and at least one initial attack strategy corresponding to a to-be-tested attack tool.
[0060] The at least one initial defense strategy configured in the to-be-tested security tool can be determined according to the software instructions issued by the manufacturer of the to-be-tested security tool.
[0061] For the initial attack strategy corresponding to the to-be-tested attack tool, the initial attack strategy corresponding thereto can be analyzed through the specific attack behaviors of the historical attack events initiated by the to-be-tested attack tool. The analysis method is prior art, and will not be described here.
[0062] S200: Obtain an effective defense strategy corresponding to each initial attack strategy according to an attack-defense mapping table. The effective defense strategy is an initial defense strategy that has defense capability for the corresponding initial attack strategy. The attack-defense mapping table is used to record the corresponding relationship between each initial attack strategy and initial defense strategy.
[0063] The attack-defense mapping table in this step can be a mapping table of existing attack technology and defense technology. For example, a digital artifact structure provided by D3FEND. The digital artifact structure can provide the mapping relationship between ATT&CK and D3FEND. Thus, at least one effective defense strategy corresponding to each initial attack strategy can be obtained according to the digital artifact structure.
[0064] ATT&CK translates known attacker behaviors into structured lists, aggregates these known behaviors into tactics and techniques, and expresses them through several matrices as well as Structured Threat Information eXpression (STIX) and Trusted Automated eXchange of Indicator Information (TAXII - an industry standard for sharing threat intelligence). Because this list presents attacker behaviors quite comprehensively as they are employed in attacking a network, it is useful for a variety of offensive and defensive metrics, representations, and other mechanisms. The goal of ATT&CK (Threat Framework) is to create an exhaustive list of known adversarial tactics and techniques used in cyberattacks. In simple terms, ATT&CK is a "Tactics, Techniques, and Common Knowledge" framework provided by MITRE, which is a curated knowledge base of 12 tactics and 244 enterprise techniques that attackers would leverage when attacking a business.
[0065] D3FEND is a knowledge base on cyber defense countermeasure techniques, more specifically a knowledge graph of cyber defense countermeasure techniques. In the simplest sense, it is a catalog of defensive cyber security techniques and knowledge of their relationship to offensive techniques.
[0066] S300: performing confrontation processing on each initial attack strategy and corresponding effective defense strategy to generate test information corresponding to each initial attack strategy.
[0067] S400: generating confrontation information of the to-be-tested security tool and the to-be-tested attack tool according to the test information.
[0068] The test information corresponding to each initial attack strategy is listed together to form the confrontation information of the to-be-tested security tool and the to-be-tested attack tool. The confrontation information is used to represent the defense effect of the to-be-tested security tool on each initial attack strategy in the to-be-tested attack tool.
[0069] The confrontation processing includes:
[0070] S301: obtaining an attack capability value of the initial attack strategy.
[0071] The attack capability value is used to represent the attack strength of the corresponding initial attack strategy. The attack capability value of each initial attack strategy can be obtained according to an existing evaluation method.
[0072] S302: obtaining a defense capability value of each corresponding effective defense strategy.
[0073] The defense capability value is used to represent the defense strength of the corresponding initial defense strategy. The defense capability value of each initial defense strategy can be obtained according to an existing evaluation method.
[0074] S303: generating test information corresponding to each initial attack strategy according to the attack capability value and the corresponding defense capability value.
[0075] The defense effect of the to-be-tested security tool on each initial attack strategy is determined by comparing the size of the attack capability value and the corresponding defense capability value. Specifically, if the attack capability value is greater than the corresponding defense capability value, the to-be-tested security tool cannot produce a defense effect on the corresponding initial attack strategy. If the attack capability value is less than the corresponding defense capability value, the to-be-tested security tool can produce a defense effect on the corresponding initial attack strategy.
[0076] In the present application, the problem that the to-be-tested security tool or attack tool cannot be obtained for testing is solved by obtaining at least one initial defense strategy corresponding to the to-be-tested security tool and at least one initial attack strategy corresponding to the to-be-tested attack tool. Then, the effective defense strategy corresponding to each initial attack strategy is obtained through the attack-defense mapping table. The attack capability value corresponding to each initial attack strategy and the defense capability value of the corresponding effective defense strategy are calculated through the confrontation test. Then, the defense effect of the to-be-tested security tool on each initial attack strategy is more accurately determined by comparing the attack capability value and the corresponding defense capability value.
[0077] In the present application, further, S301: obtaining the attack capability value of the initial attack strategy, comprises:
[0078] S311: obtaining an attack mapping table. The attack mapping table is used to record the correspondence between each initial attack strategy and the attack capability value.
[0079] S321: obtaining the attack capability value corresponding to the initial attack strategy according to the attack mapping table.
[0080] Preferably, the attack mapping table is obtained by the following steps:
[0081] S331: performing attack capability conversion processing on each initial attack strategy to generate the attack capability value corresponding to each initial attack strategy.
[0082] S341: generating the attack mapping table according to the correspondence between each initial attack strategy and the attack capability value.
[0083] The attack capability conversion processing comprises:
[0084] S351: generating the attack capability value of the initial attack strategy according to the damage level, the brand-new level and the concealment level corresponding to the initial attack strategy.
[0085] Specifically, the evaluation standard of the damage level in this step can be obtained using the existing evaluation method of the harm of network attack or virus. Preferably, the evaluation can be performed according to the propagation and the severity of the harm caused to the user when the initial attack strategy attacks.
[0086] Specifically, taking viruses as an example, five corresponding damage levels can be divided according to the following standards:
[0087] Damage level: level one. Judgment standard: the virus only spreads on a single platform locally, and does not cause any adverse effects or weak effects on the system.
[0088] Damage level: level two. Judgment standard: the virus only spreads in a local area network range or a subnet segment or spreads on a single machine with multiple platforms, causes unstable factors to the system, leads to abnormal work of other programs, and partially consumes network resources.
[0089] Damage level: level three. Judgment standard: the virus has limited Internet spreading ability, and can cause system software to crash or consume a large amount of network resources.
[0090] Damage level: level four. Judgment standard: the virus has active propagation and attack ability, or is a worm virus with two weak Internet propagation methods, and can cause data loss or network congestion.
[0091] Damage level: level five. Judgment standard: the virus is a worm with more than three propagation abilities or two strong propagation abilities. It can cause large-area data loss or block network communication, etc.
[0092] The damage levels of levels one to five gradually increase, and in the present application, the damage level assignment is proportional to the damage level. Specifically, the damage level assignments A corresponding to the damage levels of levels one to five are 50, 60, 70, 80, 90 and 100, respectively.
[0093] The new level can be determined by the interval L between the earliest time T1 when the attack strategy is discovered and the current time T2. The new level assignment is proportional to the new level.
[0094] Specifically, the new level assignment B corresponding to each new level satisfies the following condition:
[0095]
[0096] Wherein, k is a preset coefficient, k ∈ [1 day, 100 days]. L = T2-T1.
[0097] The concealment level can be determined by selecting multiple existing antivirus software to detect the attack behavior initiated by the corresponding initial attack strategy. The detection rate M is set as the concealment level. The concealment level assignment C corresponding to each concealment level satisfies the following condition: C = 100*M.
[0098] Then the attack ability value D of the initial attack strategy in the present embodiment satisfies the following condition:
[0099] In this embodiment, according to the plurality of indexes corresponding to each initial attack strategy, the attack ability value of each initial attack strategy can be calculated. Thus, the attack strength of each initial attack strategy can be more accurately reflected through the attack ability value.
[0100] In the present application, further, S302: obtaining the defense ability value of each effective defense strategy corresponding, comprising:
[0101] S312: determining the defense tool category to which the to-be-tested security tool belongs. Specifically, the category can include: firewall category, vulnerability scanning device category, traffic monitoring device category, security isolation gateway category, and IDS (Intrusion Detection Systems) category. Among them, the IDS category includes AIDS and SIDS. The firewall category includes software firewall, hardware firewall, packet filtering firewall, circuit-level gateway, rule checking firewall, proxy firewall, and cloud firewall.
[0102] S322: obtaining a defense mapping table. The defense mapping table is used to record the correspondence between each defense tool category and the basic defense ability value.
[0103] S332: generating the basic defense ability value corresponding to the to-be-tested security tool according to the defense mapping table and the defense tool category to which the to-be-tested security tool belongs.
[0104] S342: generating the defense ability value of each effective defense strategy according to the basic defense ability value and the freshness of each effective defense strategy corresponding to the to-be-tested security tool.
[0105] Since, with the extension of the defense strategy birth time, attack methods that can bypass the defense strategy will gradually appear, so the defense ability of the defense strategy will gradually decrease with the extension of the birth time. In this embodiment, the freshness E is used to represent the length of the defense strategy birth time. The defense ability value F satisfies the following condition: F=J / E; wherein, J i is the basic defense ability value of the ith effective defense strategy.
[0106] In this embodiment, since the to-be-tested security tool cannot be obtained, the defense ability corresponding thereto needs to be determined by inference based on the defense ability of the existing related known security protection tool. At the same time, since the number of existing known security protection tools is large, it is impossible to complete the defense ability test of each known security protection tool, so the known security protection tools are classified. Generally, there is a large difference in defense ability between different categories, but the defense ability of the same category is less different. Thus, the defense ability value of each initial defense strategy in the to-be-tested security tool can be more accurately evaluated and estimated through this embodiment.
[0107] In the present application, further, the defense mapping table is obtained by the following steps:
[0108] S352: Obtain a plurality of evaluation security tools corresponding to each defense tool category.
[0109] The evaluation security tool is an existing antivirus software corresponding to each defense tool category.
[0110] S362: Perform defense capability conversion processing on the plurality of evaluation security tools to generate a basic defense capability value corresponding to each defense tool category.
[0111] S372: Generate a defense mapping table according to the basic defense capability value corresponding to each defense tool category.
[0112] The defense capability conversion processing includes:
[0113] S382: Generate a sub-defense capability value corresponding to each evaluation security tool according to the device technical and tactical coverage and the counter-attack efficiency corresponding to each evaluation security tool.
[0114] The sub-defense capability value H i of the i-th evaluation security tool satisfies the following conditions: i H i = 0.3*P i + 0.7*Q .
[0115] Wherein, P i is the device technical and tactical coverage corresponding to the i-th evaluation security tool. The device technical and tactical coverage is related to the number R of attack techniques that can be defended by the corresponding evaluation security tool, which can be determined according to the attack-defense mapping table. When R∈[0,50], the corresponding P i = 60. When R∈[51,150], the corresponding P i = 75. When R∈[151,400], the corresponding P i = 90. When R∈[401,1000], the corresponding P i = 100.
[0116] Q i is the counter-attack efficiency corresponding to the i-th evaluation security tool. The counter-attack efficiency in the present embodiment can be obtained by the existing analytic hierarchy process. In order to unify the comparison standard, the obtained counter-attack efficiency value can be normalized to 0-100 by normalization method.
[0117] The evaluation tree used in the analytic hierarchy process in the present embodiment is obtained in the following manner:
[0118] The first bottom layer includes network delay, network average response time, network packet loss rate, network throughput, network reply time and the like.
[0119] The second bottom layer includes host CPU occupancy, host memory occupancy, host hard disk occupancy and the like.
[0120] The third bottom layer includes port detection accuracy, vulnerability detection accuracy, system account detection accuracy and IP detection accuracy and the like.
[0121] The first middle layer corresponding to the first bottom layer is network availability, the second middle layer corresponding to the second bottom layer is host availability, and the second middle layer corresponding to the third bottom layer is network structure vulnerability.
[0122] S392: generating a defense capability value of the defense tool category according to the plurality of sub-defense capability values.
[0123] The defense capability value F of the ith defense tool category in the embodiment is calculated according to the plurality of sub-defense capability values corresponding to each evaluation security tool. i The following conditions are met: Wherein, w is the total number of evaluation security tools.
[0124] In the embodiment, the defense capability value of the defense tool category can be calculated according to the plurality of indexes corresponding to each sub-defense capability value of the evaluation security tool.
[0125] In the present application, further, the effective defense strategies are multiple.
[0126] S303: generating test information corresponding to each initial attack strategy according to the attack capability value and the corresponding defense capability value, including:
[0127] S313: generating a total defense capability value according to the defense capability values corresponding to the plurality of effective defense strategies.
[0128] S323: generating test information corresponding to each initial attack strategy according to the attack capability value and the corresponding total defense capability value.
[0129] Since each effective defense strategy is individually defended, when an initial attack strategy corresponds to multiple effective defense strategies, the sum of the defense capability values corresponding to the multiple effective defense strategies is taken as the total defense capability value. Then, according to the size relationship between the attack capability value and the corresponding total defense capability value, test information corresponding to each initial attack strategy is generated.
[0130] In the present application, further, the defense capability value includes multiple types of sub-defense capability values.
[0131] The secondary defense capability value is obtained through the following steps:
[0132] S333: Obtain the assignment weight corresponding to the secondary defense capability value.
[0133] S343: Generate the secondary defense capability value according to the assignment weight and the defense capability value.
[0134] The secondary defense capability value includes an alarm capability value, an active defense value and an interception value. The corresponding assignment weights thereof are sequentially increased. For example, 1.2, 1 and 0.8. When the defense capability value is 60, the corresponding alarm capability value = 60*1.2 = 72. The active defense value = 60*1 = 60. The interception value = 60*0.8 = 48.
[0135] Correspondingly, the attack capability value can also correspond to multiple secondary attack capability values, such as an attack alarm capability value, an attack active defense value and an attack interception value. When the attack capability value is 60, the corresponding attack alarm capability value = 60*1.3 = 78. The attack active defense value = 60*1.1 = 66. The attack interception value = 60*0.7 = 42.
[0136] When performing comparison, the same items are compared to generate the test information corresponding to each initial attack strategy.
[0137] According to a second aspect of the present application, as shown in Figure 2 , there is provided an attack-defense confrontation test device, comprising:
[0138] A first obtaining module is configured to obtain at least one initial defense strategy corresponding to a to-be-tested security tool and at least one initial attack strategy corresponding to a to-be-tested attack tool.
[0139] A second obtaining module is configured to obtain, according to an attack-defense mapping table, an effective defense strategy corresponding to each initial attack strategy. The effective defense strategy is an initial defense strategy that has a defense capability for the corresponding initial attack strategy. The attack-defense mapping table is configured to record the corresponding relationship between each initial attack strategy and initial defense strategy.
[0140] A confrontation processing module is configured to perform confrontation processing on each initial attack strategy and the corresponding effective defense strategy to generate test information corresponding to each initial attack strategy.
[0141] A generating module is configured to generate confrontation information of the to-be-tested security tool and the to-be-tested attack tool according to the test information.
[0142] The confrontation processing includes:
[0143] An attack capability value of the initial attack strategy is obtained.
[0144] An attack capability value corresponding to each initial attack strategy is calculated.
[0145] According to the attack capability value and the corresponding defense capability value, test information corresponding to each initial attack strategy is generated.
[0146] In the present application, at least one initial defense strategy corresponding to the security tool to be tested and at least one initial attack strategy corresponding to the attack tool are obtained to solve the problem that the security tool or the attack tool to be tested cannot be obtained. Then, through the attack-defense mapping table, the effective defense strategy corresponding to each initial attack strategy is obtained. Then, through the confrontation test, the attack capability value corresponding to each initial attack strategy and the defense capability value of the corresponding effective defense strategy are calculated. Then, by comparing the attack capability value and the corresponding defense capability value, the defense effect of the security tool to each initial attack strategy is more accurately determined.
[0147] The embodiment of the present application also provides a non-transitory computer readable storage medium, which can be arranged in an electronic device to save at least one instruction or at least one program related to a method in the method embodiment, and the at least one instruction or the at least one program is loaded and executed by the processor to realize the method provided by the above-mentioned embodiment.
[0148] The embodiment of the present application also provides an electronic device, which comprises a processor and the aforementioned non-transitory computer readable storage medium.
[0149] The embodiment of the present application also provides a computer program product, which comprises program code, and when the program product is run on the electronic device, the program code is used to make the electronic device execute the steps in the method according to the various exemplary embodiments of the present application described in the present specification.
[0150] Although some specific embodiments of the present application have been described in detail by examples, those skilled in the art should understand that the above examples are only for illustration, but not for limiting the scope of the present application. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present application. The scope of the present application is defined by the appended claims.
Claims
1. A method of attack-defense confrontation testing, characterized in that, The method comprises the following steps: Obtaining at least one initial defense strategy corresponding to the to-be-tested security tool and at least one initial attack strategy corresponding to the to-be-tested attack tool; According to the attack-defense mapping table, obtaining the effective defense strategy corresponding to each initial attack strategy; the effective defense strategy is the initial defense strategy that has defense capability to the corresponding initial attack strategy; the attack-defense mapping table is used to record the corresponding relationship between each initial attack strategy and initial defense strategy; Conducting confrontation processing on each initial attack strategy and the corresponding effective defense strategy to generate test information corresponding to each initial attack strategy; According to the test information, generating confrontation information of the to-be-tested security tool and the to-be-tested attack tool; The confrontation processing comprises: Obtaining the attack capability value of the initial attack strategy; Obtaining the defense capability value of each corresponding effective defense strategy; According to the attack capability value and the corresponding defense capability value, generating the test information corresponding to each initial attack strategy; Obtaining the attack capability value of the initial attack strategy comprises: Obtaining an attack mapping table; the attack mapping table is used to record the corresponding relationship between each initial attack strategy and attack capability value; According to the attack mapping table, obtaining the attack capability value corresponding to the initial attack strategy; The attack mapping table is obtained through the following steps: Conducting attack capability conversion processing on each initial attack strategy to generate the attack capability value corresponding to each initial attack strategy; According to the corresponding relationship between each initial attack strategy and the attack capability value, generating an attack mapping table; The attack capability conversion processing comprises: According to the damage level, the brand-new level and the concealment level corresponding to the initial attack strategy, generating the attack capability value of the initial attack strategy; Obtaining the defense capability value of each corresponding effective defense strategy comprises: Determining the defense tool category to which the to-be-tested security tool belongs; Obtaining a defense mapping table; the defense mapping table is used to record the corresponding relationship between each defense tool category and basic defense capability value; According to the defense mapping table and the defense tool category to which the to-be-tested security tool belongs, generating the basic defense capability value corresponding to the to-be-tested security tool; According to the basic defense capability value and the brand-new degree of each effective defense strategy corresponding to the to-be-tested security tool, generating the defense capability value of each effective defense strategy; The defense mapping table is obtained through the following steps: Obtaining a plurality of evaluation security tools corresponding to each defense tool category; Conducting defense capability conversion processing on a plurality of evaluation security tools to generate the basic defense capability value corresponding to each defense tool category; According to the basic defense capability value corresponding to each defense tool category, generating the defense mapping table; The defense capability conversion processing comprises: According to the device skill and tactic coverage and the confrontation attack efficiency corresponding to each evaluation security tool, generating the sub-defense capability value corresponding to each evaluation security tool; According to a plurality of sub-defense capability values, generating the defense capability value of the defense tool category.
2. The method of claim 1, wherein, The effective defense strategy is multiple. According to the attack capability value and the corresponding defense capability value, test information corresponding to each initial attack strategy is generated, including: According to the defense capability values corresponding to the plurality of effective defense strategies, a total defense capability value is generated; According to the attack capability value and the total defense capability value, test information corresponding to each initial attack strategy is generated.
3. The method of claim 2, wherein, The defense capability value includes a plurality of types of secondary defense capability values; The secondary defense capability value is obtained by the following steps: Obtain the assignment weight corresponding to the secondary defense capability value; According to the assignment weight and the defense capability value, the secondary defense capability value is generated.
4. An attack-defense confrontation test apparatus characterized by comprising: Including: The first acquisition module is used for acquiring at least one initial defense strategy corresponding to the to-be-tested security tool and at least one initial attack strategy corresponding to the to-be-tested attack tool; The second acquisition module is used for acquiring, according to an attack-defense mapping table, an effective defense strategy corresponding to each initial attack strategy; the effective defense strategy is an initial defense strategy that has defense capability against the corresponding initial attack strategy; the attack-defense mapping table is used for recording the correspondence between each initial attack strategy and initial defense strategy; The confrontation processing module is used for performing confrontation processing on each initial attack strategy and the corresponding effective defense strategy, to generate test information corresponding to each initial attack strategy; The generation module is used for generating confrontation information of the to-be-tested security tool and the to-be-tested attack tool according to the test information; The confrontation processing includes: Obtain the attack capability value of the initial attack strategy; Obtain the defense capability value of each corresponding effective defense strategy; According to the attack capability value and the corresponding defense capability value, test information corresponding to each initial attack strategy is generated; Obtaining the attack capability value of the initial attack strategy includes: Obtain an attack mapping table; the attack mapping table is used for recording the correspondence between each initial attack strategy and attack capability value; According to the attack mapping table, the attack capability value corresponding to the initial attack strategy is obtained; The attack mapping table is obtained by the following steps: Perform attack capability conversion processing on each initial attack strategy to generate the attack capability value corresponding to each initial attack strategy; According to the correspondence between each initial attack strategy and the attack capability value, an attack mapping table is generated; The attack capability conversion processing includes: According to the damage level, the brand-new level and the concealment level corresponding to the initial attack strategy, the attack capability value of the initial attack strategy is generated; Obtaining the defense capability value of each corresponding effective defense strategy includes: Determine the defense tool category to which the to-be-tested security tool belongs; Obtain a defense mapping table; the defense mapping table is used for recording the correspondence between each defense tool category and basic defense capability value; According to the defense mapping table and the defense tool category to which the to-be-tested security tool belongs, a basic defense capability value corresponding to the to-be-tested security tool is generated; According to the basic defense capability value and the brand-new degree of each effective defense strategy corresponding to the to-be-tested security tool, the defense capability value of each effective defense strategy is generated; The defense mapping table is obtained by the following steps: Obtain a plurality of evaluation security tools corresponding to each defense tool category; The defense capability conversion processing is performed on the plurality of evaluation security tools to generate a basic defense capability value corresponding to each defense tool category; The defense mapping table is generated according to the basic defense capability value corresponding to each defense tool category; The defense capability conversion processing includes: The sub-defense capability value corresponding to each evaluation security tool is generated according to the equipment and tactics coverage and the attack counter-effectiveness of each evaluation security tool; The defense capability value of the defense tool category is generated according to the plurality of sub-defense capability values. 5.A non-transitory computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a processor, cause the processor to perform the method of any one of claims 1 to 4. The computer program, when executed by a processor, implements the attack and defense confrontation test method according to any one of claims 1 to 3.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: The processor, when executing the computer program, implements the attack and defense confrontation test method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Attack-oriented network security situation prediction method, device and system
CN108494810A
Method, system and equipment for testing defensive performance of service system and medium
CN114611110A