Security testing tool anti-theft method, network target range system and electronic device

By setting target range identifiers and authorization authentication for security testing tools, combined with block encryption and whitelisting, and real-time detection of outflowing data, the problem of security testing tools being stolen in network target ranges is solved. Internal circulation restrictions and authorization controls for the tools are implemented, improving the comprehensiveness of protection.

CN116488888BActive Publication Date: 2026-08-04PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PENG CHENG LAB
Filing Date
2023-04-12
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In existing technologies, security testing tools are easily stolen during attack and defense drills in network ranges, especially in the absence of hardware support. Software encryption methods are easily cracked, leading to tool leaks.

Method used

By setting a target range identifier for security testing tools and monitoring and blocking outflowing data in real time under the management of the authorization and authentication server, combined with block encryption and whitelist settings, the tools are restricted from leaving the target range's external network. At the same time, authorization and authentication are performed to ensure that only authorized tools can use them.

Benefits of technology

It effectively prevents security testing tools from leaking out of the target range's external network, achieving dual protection, adapting to different attack and defense exercise scenarios, and increasing the comprehensiveness of tool protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116488888B_ABST
    Figure CN116488888B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a security test tool anti-theft method, a network target range system and electronic equipment. The security test tool is provided with a target range identifier, and then the security test tool carrying the target range identifier is distributed to a player virtual machine for attack and defense exercise. In the exercise process, the data sent by the player virtual machine to the outside network of the target range is detected in real time. When it is detected that the target range identifier is carried in the data, it is confirmed that the data is the security test tool or part of the security test tool, and the data is intercepted. Meanwhile, the security test tool is authorized and authenticated by an authorization authentication server, and the security test device can be installed or used only after the authorization authentication is passed. The embodiment of the application protects the security test tool from the network target range system level and the software level, can adapt to different attack and defense exercise scenes, and further increases the comprehensiveness of the security test tool protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to a method for preventing theft of security testing tools, a network range system, and electronic equipment. Background Technology

[0002] A cyber range is a technology or product based on virtualization that simulates and reproduces the operational status and environment of network architecture, system equipment, and business processes in real cyberspace, in order to more effectively realize learning, research, testing, competition, and exercises related to cybersecurity.

[0003] In related technologies, security testing software is primarily prevented from being stolen and misused through software and hardware encryption. Software encryption is vulnerable to theft through password brute-force attacks, unauthorized modification of program files, or illegal sharing of serial numbers. Hardware encryption requires hardware support, such as plug-in verification hardware. However, in different network range exercises, the host machines for virtual machines may differ, making plug-in hardware unavailable. How to more comprehensively prevent the theft of security testing tools during attack and defense exercises is a pressing issue that needs to be discussed. Summary of the Invention

[0004] This application provides a method for preventing theft of security testing tools, as well as a network range system, electronic device, computer-readable storage medium, and computer program product, which aims to more comprehensively prevent security testing tools from being stolen during attack and defense exercises.

[0005] In a first aspect, embodiments of this application provide a method for preventing the theft of security testing tools, applied in a network range. The network range is equipped with an authorization and authentication server and a resource leakage prevention system. The method includes: in response to acquiring a security testing tool, setting a range identifier and an authorization and authentication program for the security testing tool, wherein the range identifier is used to mark the data of the security testing tool during transmission, and the authorization and authentication program is used to enable a contestant virtual machine to make an authorization and authentication request according to authorization rules; distributing the security testing tool to the contestant virtual machine, so that the contestant virtual machine sends an authorization and authentication request to the authorization and authentication server according to the authorization rules; receiving the authorization and authentication request through the authorization and authentication server, sending a corresponding authorization certificate to the contestant virtual machine, so that the contestant virtual machine installs the authorization certificate in a pre-deployed authorization and authentication container and uses the authorized security testing tool to conduct attack and defense drills; detecting outflow data transmitted by the contestant virtual machine to the network outside the range in real time through the resource leakage prevention system; and intercepting the outflow data when the outflow data is detected to carry the range identifier.

[0006] Furthermore, setting the target range identifier for the security testing tool includes: encrypting the security testing tool; setting the target range identifier for the security testing tool during the encryption process; distributing the security testing tool to the contestant's virtual machine includes: distributing the security testing tool and the corresponding encryption / decryption public key to the contestant's virtual machine, wherein the encryption / decryption public key is generated during the encryption process of the security testing tool.

[0007] Furthermore, when the encryption process is a block encryption process, setting the target range identifier for the security testing tool includes: dividing the security testing tool into several data blocks; performing block encryption on the data blocks to obtain the encrypted blocks corresponding to the data blocks; and setting the target range identifier for each encrypted block.

[0008] Furthermore, the method also includes: pre-acquiring gateway external link configuration information; setting a whitelist for the gateway external link, so that the contestant virtual machine can access the specified address according to the gateway external link in the whitelist, and send the data generated during the attack and defense exercise to the specified address.

[0009] Furthermore, the target range identifier includes at least one of the following: a string of characters randomly generated according to a preset length; a string of characters generated according to the information of the network target range; or a string of characters generated according to the information of the current attack and defense exercise session.

[0010] Furthermore, receiving the authorization and authentication request through the authorization and authentication server includes: when the authorization and authentication server fails to authenticate, prohibiting the contestant's virtual machine from using the security testing tool, or destroying the security testing tool.

[0011] Furthermore, the authorization rules shall include at least one of the following: usage time, expiration time, and number of uses;

[0012] If the authorization rules include the usage time, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following steps are also included:

[0013] When the contestant's virtual machine uses the security testing tool for the time specified in the usage time, the authorization and authentication server responds to the contestant's virtual machine's re-initiated authorization and authentication request by renewing the corresponding authorization certificate or sending a new authorization certificate to the contestant's virtual machine.

[0014] If the authorization rules include the expiration time, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the method further includes:

[0015] When the contestant's virtual machine uses the security testing tool for the time it expires, the contestant's virtual machine is prohibited from using the security testing tool, or the security testing tool is destroyed.

[0016] If the authorization rules include the number of uses, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following steps are also included:

[0017] If the contestant's virtual machine uses the security testing tool more times than the specified number of uses, the contestant's virtual machine will be prohibited from using the security testing tool, or the security testing tool will be destroyed.

[0018] Secondly, embodiments of this application provide a network testing range system, including a tool management module, which, in response to acquiring a security testing tool, sets a testing range identifier and an authorization authentication procedure for the security testing tool. The testing range identifier is used to mark the data of the security testing tool during transmission, and the authorization authentication procedure enables a virtual machine (VM) to request authorization authentication according to authorization rules. A tool distribution module distributes the security testing tool to the VM, enabling the VM to send an authorization authentication request to the authorization authentication server according to the authorization rules. An authorization management module receives the authorization authentication request through the authorization authentication server and sends a corresponding authorization certificate to the VM, enabling the VM to install the authorization certificate in a pre-deployed authorization authentication container and use the authorized security testing tool for attack and defense drills. A data detection module detects outflow data transmitted by the VM to the external network of the testing range in real time using a resource leakage prevention system. A data interception module intercepts the outflow data when it detects that the outflow data carries the testing range identifier.

[0019] Thirdly, embodiments of this application provide an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the anti-theft method for security testing tools as described in the first aspect.

[0020] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, wherein when a computer executes the computer program, it implements the anti-theft method for security testing tools as described in the first aspect.

[0021] Fifthly, embodiments of this application provide a computer program product, including a computer program or computer instructions, wherein the computer program or computer instructions are stored in a computer-readable storage medium, a processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium, and the processor executes the computer program or computer instructions, causing the computer device to perform the anti-theft method for security testing tools as described in the first aspect.

[0022] In this embodiment, a target range identifier is set for the security testing tool. The security testing tool carrying the target range identifier is then assigned to a participant's virtual machine for attack and defense drills. During the drills, data sent by the participant's virtual machine to the external network is monitored in real time. When the target range identifier is detected in the data, it can be confirmed that the data belongs to the security testing tool or a part of it, and the data is intercepted. Simultaneously, the security testing tool is authorized and authenticated through an authorization and authentication server. Only after successful authorization and authentication can the security testing device be installed or used. This scheme effectively restricts the circulation of the security testing tool within the target range, preventing it from leaking out of the external network and causing leakage. Furthermore, the authorization and authentication of the security testing tool ensures that only authorized and authenticated tools can be installed and used normally. This dual protection of the security testing tool at both the network target range system level and the software level further enhances the comprehensiveness of the security testing tool's protection.

[0023] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the description, claims and drawings. Attached Figure Description

[0024] Figure 1 A schematic diagram of the structure of a federal range system provided in one embodiment of this application;

[0025] Figure 2 A flowchart illustrating a method for preventing theft of a security testing tool provided in an embodiment of this application;

[0026] Figure 3 A schematic diagram of a system for authorizing and certifying a security testing tool provided as an example in this application;

[0027] Figure 4A system schematic diagram illustrating the detection data of a resource leakage prevention system provided as an example in this application;

[0028] Figure 5 A system diagram illustrating the gateway external link configuration provided as an example in this application;

[0029] Figure 6 This is a schematic diagram of the structure of a network range system provided in an embodiment of this application;

[0030] Figure 7 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation

[0031] To make the objectives, technical methods, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0032] It should be noted that although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0033] In the description of the embodiments of this application, unless otherwise expressly limited, terms such as "setting," "installing," and "connecting" should be interpreted broadly. Those skilled in the art can reasonably determine the specific meaning of the above terms in the embodiments of this application in conjunction with the specific content of the technical solution. In the embodiments of this application, terms such as "furthermore," "exemplarily," or "optionally" are used to indicate that they are examples, illustrations, or descriptions, and should not be construed as being more preferred or more advantageous than other embodiments or design solutions. The use of terms such as "furthermore," "exemplarily," or "optionally" is intended to present the relevant concepts in a specific manner.

[0034] A cyber range is a technology or product based on virtualization that simulates and reproduces the operational status and environment of network architecture, system equipment, and business processes in real cyberspace, in order to more effectively realize learning, research, testing, competition, and exercises related to cybersecurity.

[0035] In related technologies, security testing software is primarily prevented from being stolen and misused through software and hardware encryption. Software encryption employs methods such as serial numbers and online registration / activation, requiring users to register and activate with a specific serial number before normal use. While software encryption is cost-effective, it is vulnerable to theft through password brute-force attacks, unauthorized modification of program files, or illegal sharing of serial numbers. Hardware encryption requires hardware support, such as plug-in verification hardware. However, in the environment of a network testing range, security testing tools are deployed on virtual machines based on the range system, and the host machine for each exercise may be different, thus lacking the conditions for plug-in hardware assistance.

[0036] To address the aforementioned issues, this application provides a method for preventing the theft of security testing tools, as well as a network range system, electronic device, computer-readable storage medium, and computer program product. By setting a range identifier for the security testing tool, and then distributing the security testing tool carrying the range identifier to a participant's virtual machine for attack and defense drills, the method monitors data sent by the participant's virtual machine to the external network in real time during the drills. When the range identifier is detected in the data, it can be confirmed that the data belongs to the security testing tool or a portion thereof, and the data is intercepted. Simultaneously, the security testing tool is authorized and authenticated through an authorization and authentication server. Only after successful authorization and authentication can the security testing device be installed or used. This application, through the above scheme, effectively restricts the circulation of security testing tools within the range, preventing them from leaking out of the external network and causing leakage. Furthermore, the authorization and authentication of the security testing tool ensures that only authorized and authenticated tools can be installed and used normally. This dual protection of the security testing tool at both the network range system level and the software level adapts to different attack and defense drill scenarios, further increasing the comprehensiveness of security testing tool protection. This application also sets up whitelists for each configured external link based on the configured gateway external links, so that contestants can only access designated addresses, preventing contestants from sending data to irrelevant addresses and causing the security testing tools to be leaked, thereby more comprehensively preventing the security testing tools from being illegally stolen.

[0037] The embodiments of this application will be further described below with reference to the accompanying drawings.

[0038] Figure 1 This is a schematic diagram of the structure of a federal range system provided in one embodiment of this application, as shown below. Figure 1 As shown, the system includes a red and blue team management system, a resource management system, a resource leakage prevention system, player virtual machines, a target range gateway, and an authorization and authentication server.

[0039] The resource management system communicates with both the red / blue team management system and the contestants' virtual machines. It stores security testing tools, encrypts them, sets target range identifiers, and distributes these tools to contestants' virtual machines as needed.

[0040] The Red / Blue Team management system communicates with both the contestant virtual machines and the resource management system. It obtains the encryption / decryption public keys generated by the security testing tool in the resource management system and distributes these keys to the necessary contestant virtual machines. The Red / Blue Team management system also configures the authorization and authentication process for the security testing tool.

[0041] The resource leakage prevention system connects to the contestant's virtual machine and the external network of the testing range. It is used to detect data exchanged between the contestant's virtual machine and the external network, such as data generated during communication between the contestant's virtual machine and a personal computer.

[0042] The authorization and authentication server establishes a communication connection with the contestant's virtual machine. The server authenticates the authorization requests initiated by the contestant's virtual machine based on the authorization and authentication program of the security testing tool. If authentication is successful, the server sends an authorization certificate to the contestant's virtual machine, enabling it to install or use the corresponding security testing tool.

[0043] The contestant virtual machine is used for contestants to conduct attack and defense drills. For example, contestants can use the contestant virtual machine to attack or defend against targets within the range system, or they can use the contestant virtual machine to attack or defend against targets outside the range system.

[0044] The range gateway is used to forward data transmissions in the range system so that data generated during attack and defense exercises can reach the target address according to a preset path.

[0045] Understandably, the red team refers to the attacker in the network attack and defense exercise, and the blue team refers to the defender. The red and blue team management system is also responsible for allocating the encryption and decryption public keys required during the attack and defense exercise to both the attacker and the defender, as well as security testing tools with authorization and authentication procedures.

[0046] Understandably, security testing tools include software used for cyberattacks and software used for cyber defense.

[0047] It is understandable that the Red and Blue Team Management System, Resource Management System, and Resource Leakage Prevention System are all subsystems of the Federal Range System; each subsystem can be deployed on the same server, on different servers, or in a distributed server cluster composed of multiple different servers.

[0048] It is understandable that a federal range refers to a network attack and defense training range composed of multiple interconnected network ranges in different regions.

[0049] This application embodiment sets a target range identifier for the security testing tool, and then distributes the security testing tool carrying the target range identifier to the contestant's virtual machine for attack and defense drills. During the drills, the data sent by the contestant's virtual machine to the external network is monitored in real time. When the target range identifier is detected in the data, it can be confirmed that the data belongs to the security testing tool or part of the security testing tool, and the data is intercepted. At the same time, the security testing tool is authorized and authenticated through an authorization and authentication server. Only after the authorization and authentication is passed can the security testing device be installed or used. Through the above scheme, this application embodiment restricts the circulation of the security testing tool to within the target range, which can effectively prevent the security testing tool from leaking out of the external network and causing leakage. At the same time, the authorization and authentication of the security testing tool ensures that only the authorized and authenticated security testing tool can be installed and used normally. This dual protection of the security testing tool from the network target range system level and the software level can adapt to different attack and defense drill scenarios and further increase the comprehensiveness of the security testing tool protection.

[0050] Figure 2 This is a flowchart of a method for preventing theft of a security testing tool provided in an embodiment of this application. Figure 2 As shown, this method for preventing theft of security testing tools can be applied to at least the following: Figure 1 The federal range or other cyber range shown is equipped with an authorization authentication server and a resource leakage prevention system. The anti-theft method for this security testing tool includes, but is not limited to, steps S1100, S1200, S1300, S1400, and S1500.

[0051] Step S1100: In response to obtaining the security testing tool, set a target range identifier and an authorization authentication procedure for the security testing tool. The target range identifier is used to mark the data of the security testing tool when transmitting the security testing tool, and the authorization authentication procedure is used to enable the contestant virtual machine to make an authorization authentication request according to the authorization rules.

[0052] In step S1100:

[0053] Security testing tools include software used for network attacks and software used for network defense in network attack and defense drills;

[0054] Range identifiers refer to identifiers inserted into the program code of security testing tools. When a security testing tool is sent to an external network of a range, the range identifier can be identified from its corresponding data stream.

[0055] The authorization and authentication program is a piece of code added when the security testing tool is packed. By setting the authorization and authentication program in the security testing tool, an additional process is started to monitor the operation of the security testing tool while the security testing tool performs its normal functions. At the same time, it interacts with the authorization server for authentication according to the authorization rules contained in the authorization and authentication program.

[0056] In one embodiment, step S1100, setting the range identifier for the security testing tool is achieved through the following steps: encrypting the security testing tool; and setting the range identifier for the security testing tool during the encryption process. The federated range system stores and encrypts all acquired security testing tools through the resource management system, and sets the range identifier in the program code of the security testing tool during the encryption process. It is understood that the encryption process for the security testing tool can also be performed through other modules or subsystems of the federated range system, and is not specifically limited here.

[0057] After obtaining the security testing tools from the federal test range, a test range identifier is set during the encryption process of the security testing tools to prevent the test range identifier from being obtained in advance by other unrelated modules or users.

[0058] In one embodiment, when the encryption process is block encryption, setting a target range identifier for the security testing tool includes: dividing the security testing tool into several data blocks; performing block encryption on the data blocks to obtain encrypted blocks corresponding to the data blocks; and setting a target range identifier for each encrypted block. For block encryption tools, inserting a target range identifier for each encrypted block during encryption can effectively prevent attackers from stealing and exploiting parts of the security testing tool's functionality.

[0059] In one embodiment, the target range identifier includes at least one of the following: a string of characters randomly generated according to a preset length; a string of characters generated according to information about the network target range; or a string of characters generated according to information about the current attack and defense exercise session. Unlike conventional software watermarks, which typically contain information such as the software owner and user identity, and are usually quite long, obvious, and easily discovered, this embodiment inserts a short string of characters of a preset length into the security testing tool. This effectively hides the target range identifier, preventing it from being discovered by attackers, while also serving a detection purpose.

[0060] Step S1200: Distribute the security testing tool to the contestant's virtual machine, enabling the contestant's virtual machine to send an authorization and authentication request to the authorization and authentication server according to the authorization rules. After the resource management system distributes the security testing tool to the contestant's virtual machine, the contestant's virtual machine obtains the authorization rules from the authorization and authentication program carried by the security testing tool, and starts a separate process to send an authorization and authentication request to the authorization and authentication server according to the authorization rules.

[0061] In step S1200, the contestant virtual machine refers to the virtual terminal within the federal range used by contestants to conduct attack and defense drills.

[0062] In one embodiment, step S1200 further includes: distributing the security testing tool to the contestant virtual machine, which includes: distributing the security testing tool and the corresponding encryption / decryption public key to the contestant virtual machine, wherein the encryption / decryption public key is generated when encrypting the security testing tool. The distributed encryption / decryption public key corresponding to the security testing tool is sent to the contestant virtual machine so that the contestant virtual machine can decrypt and use the security testing tool based on the encryption / decryption public key.

[0063] Step S1300: Receive the authorization and authentication request through the authorization and authentication server, and send the corresponding authorization certificate to the contestant's virtual machine so that the contestant's virtual machine installs the authorization certificate in the pre-deployed authorization and authentication container and uses the authorized security testing tools to conduct attack and defense drills.

[0064] The federal testing range system receives authorization requests from contestant virtual machines via an authorization and authentication server. Upon successful authorization and authentication, the system sends the corresponding authorization certificate to the contestant's virtual machine. The contestant's virtual machine installs and stores the authorization certificate in a pre-deployed authorization and authentication container. During the validity period of the authorization certificate, the contestant's virtual machine can install and use the security testing tools corresponding to the authorization certificate.

[0065] In step S1300, the authorization and authentication container refers to the storage space pre-deployed in the contestant's virtual machine for storing authorization evidence; the authorized security testing tool refers to the security testing tool corresponding to the authorization certificate obtained after the contestant's virtual machine sends an authorization and authentication request.

[0066] In one embodiment, an authorization and authentication server is deployed in the federal range system, and an authorization and authentication container is pre-deployed on the virtual machines allocated to participants. The authorization and authentication server receives requests from the virtual machines to download tools. The server verifies the identity of the requesting user and assigns an authorization method and rules. Specifically, after successful authentication, the server sets the authorization method for the tool based on the needs of the exercise scenario, the threat level of the tool, and the confidentiality level, allocating authorization rules as needed for each tool required by each user. The virtual machine receives the authorization certificate assigned by the server and installs it locally, i.e., in the authorization and authentication container. The security testing tools deployed locally on the virtual machine can then obtain authorization and be used. During use, the authorization certificate is automatically destroyed periodically, and the security testing tools need to periodically send authorization and authentication requests and status confirmations to the authorization and authentication server to ensure their availability.

[0067] In one embodiment, step S1300 further includes: when the authorization authentication server fails to authenticate, prohibiting the contestant's virtual machine from using the security testing tool, or destroying the security testing tool. By disabling or destroying the security testing tool that is not authorized or has failed authentication, the theft of the security testing tool can be effectively prevented.

[0068] In one embodiment, the authorization rules include at least one of the following: usage time, expiration time, and number of uses;

[0069] If the authorization rules include usage time, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following is also included:

[0070] When the contestant's virtual machine uses the security testing tool for the time limit, the authorization and authentication server responds to the contestant's virtual machine's renewed authorization and authentication request, renews the corresponding authorization certificate, or resends a new authorization certificate to the contestant's virtual machine.

[0071] If the authorization rules include an expiration time, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following steps are also included:

[0072] When a contestant's virtual machine uses a security testing tool for an extended period, the contestant's virtual machine will be prohibited from using the security testing tool, or the security testing tool will be destroyed.

[0073] If the authorization rules include the number of uses, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following is also included:

[0074] If a contestant's virtual machine uses the security testing tool more times than the permitted limit, the contestant's virtual machine will be prohibited from using the security testing tool, or the security testing tool will be destroyed.

[0075] By configuring an authorization and authentication process within the security testing tool, and performing real-time authorization and authentication on the tool according to the authorization rules, it's equivalent to simultaneously launching a separate process to monitor the tool's operation and interact with the authorization server for authentication based on the rules, while the tool is performing its normal functions. If the interaction is not completed within the specified time, the security testing tool's process is stopped, and related files are destroyed.

[0076] It's understandable that conventional encryption authentication methods in related technologies are one-time authentications. This is because in an internet environment, network conditions can significantly impact real-time authentication, potentially leading to software crashes, data deletion, and overall loss. Furthermore, the consequences of unauthorized software are less severe than those of unauthorized security testing tools, thus requiring only one-time authentication. However, in the federal test range system described in this application, the security testing tool is only permitted to run within the test range's intranet environment. Therefore, it can perform multiple authorization authentication interactions in real-time according to authorization rules while effectively ensuring network quality during the authentication process, avoiding losses caused by network problems.

[0077] To illustrate this more clearly, let's take a separate authorization and authentication interaction as an example. Figure 3 A schematic diagram of a system for authorizing and certifying a security testing tool provided as an example in this application is shown below. Figure 3 As shown, the resource management system sends the stored security testing tools to the red team / blue team management system. The red team / blue team management system sets up an authorization and authentication process for the security testing tools and adds authorization rules, including usage time, expiration time, and number of uses. The red team / blue team management system then distributes the processed security testing tools to the contestant's virtual machine. The contestant's virtual machine interacts with the authorization and authentication server in real time according to the authorization rules. If the authorization and authentication is successful, the contestant's virtual machine obtains the corresponding authorization certificate and is able to install and use the security testing tools corresponding to the authorization certificate.

[0078] Step S1400: Detect the outflow of data transmitted from the contestant's virtual machine to the external network of the target range in real time through the resource leakage prevention system.

[0079] Step S1500: If the outflowing data is detected to carry a target range identifier, the outflowing data is intercepted.

[0080] To illustrate this more clearly, let's take the detection of outflow data as an example. Figure 4 This is a system diagram illustrating the detection data of a resource leakage prevention system provided as an example in this application. For example... Figure 4As shown, this example illustrates an attack-defense exercise involving both external attacks on internal and external targets. The attacking player's virtual machine is deployed within the federated range system, while the attacking player's personal computer needs to connect remotely to the attacking machine within the federated range system. The player's personal computer establishes a remote connection with the player's virtual machine through a resource leakage prevention system (RSMS). All control information from the personal computer, feedback information from the player's virtual machine, and other interactive information between the player's virtual machine and the personal computer generated during the attack-defense exercise must pass through the RSMS. During the attack-defense exercise, data traffic within the federated range system is monitored in real time. The RSMS, acting as a channel connecting the federated range's internal network and external networks, detects and analyzes past data. If no range tag is matched, passage is allowed; if a range tag is matched, data transmission from the corresponding player's virtual machine is interrupted, and the administrator is notified.

[0081] Steps S1100-S1500 of this embodiment involve setting a target range identifier for the security testing tool and then assigning the security testing tool carrying the target range identifier to the contestant's virtual machine for attack and defense drills. During the drills, the data sent by the contestant's virtual machine to the external network is monitored in real time. When the target range identifier is detected in the data, it can be confirmed that the data is a security testing tool or part of a security testing tool, and the data is intercepted. At the same time, the security testing tool is authorized and authenticated through an authorization and authentication server. Only after the authorization and authentication is passed can the security testing device be installed or used. This restricts the circulation of the security testing tool to within the target range, effectively preventing the security testing tool from leaking out of the external network and causing leakage. The authorization and authentication of the security testing tool ensures that only authorized and authenticated security testing tools can be installed and used normally. This provides dual protection for the security testing tool from both the network target range system level and the software level, which can adapt to different attack and defense drill scenarios and further increase the comprehensiveness of the security testing tool's protection.

[0082] In one embodiment, the security testing tool anti-theft method of this application further includes at least the following steps: pre-acquiring gateway external link configuration information; setting a whitelist for the gateway external link so that the contestant's virtual machine can access the specified address based on the gateway external link in the whitelist, and send the data generated during the attack and defense exercise to the specified address.

[0083] Figure 5 This is a system diagram illustrating a gateway external link configuration provided as an example in this application. Figure 5As shown, this example illustrates two scenarios in a cyberattack exercise: internal attack and external attack. The internal attack scenario involves a participant directly connecting to the federal range system from a computer on the same network segment as the participant's virtual machine within the federal range system to attack targets within the range. The external attack scenario involves attacking targets outside the federal range system. Before conducting the cyberattack exercise at the federal range, gateway external links are configured. Multiple external links are configured as needed, and a whitelist is set for each cyberattack exercise. This means that the gateway external links required for the corresponding exercise are added to the whitelist. During the network cyberattack exercise, the participant's virtual machine can only access the addresses specified by the whitelisted gateway external links, restricting the participant's virtual machine to access machines with specific IPs. This effectively prevents the leakage of security testing tools.

[0084] Figure 6 This is a schematic diagram of the structure of a network range system provided in one embodiment of this application. For example... Figure 6 As shown, the network range system 2000 includes, but is not limited to:

[0085] The tool management module 2100 is used to set a target range identifier and an authorization authentication program for the security testing tool in response to obtaining the security testing tool. The target range identifier is used to mark the data of the security testing tool when transmitting the security testing tool, and the authorization authentication program is used to enable the contestant virtual machine to make an authorization authentication request according to the authorization rules.

[0086] The tool distribution module 2200 is used to distribute security testing tools to contestant virtual machines, so that the contestant virtual machines can send authorization and authentication requests to the authorization and authentication server according to the authorization rules.

[0087] The authorization management module 2300 is used to receive authorization authentication requests through the authorization authentication server, send the corresponding authorization certificate to the contestant virtual machine, so that the contestant virtual machine installs the authorization certificate in the pre-deployed authorization authentication container and uses the authorized security testing tools to conduct attack and defense drills.

[0088] The data detection module 2400 is used to detect the outflow of data transmitted from the contestant's virtual machine to the external network of the target range in real time through the resource leakage prevention system.

[0089] The data interception module 2500 is used to intercept outflowing data when it detects that the outflowing data carries a target range identifier.

[0090] Optionally, the tool management module 2100 is specifically used for: encrypting the security testing tool; and setting a target range identifier for the security testing tool during the encryption process.

[0091] The tool distribution module 2200 is specifically used to distribute the security testing tool and the corresponding encryption / decryption public key to the contestant's virtual machine. The encryption / decryption public key is generated when the security testing tool is encrypted.

[0092] Optionally, when the encryption process is block encryption, the tool management module 2100 is further specifically used to: divide the security testing tool into several data blocks; perform block encryption on the data blocks to obtain encrypted blocks corresponding to the data blocks; and set a target range identifier for each encrypted block.

[0093] Optionally, the target range identifier includes at least one of the following: a string of characters randomly generated according to a preset length; a string of characters generated according to the information of the network target range; or a string of characters generated according to the information of the current attack and defense exercise session.

[0094] Optionally, the network range system 2000 also includes a gateway external link management module (not shown). The gateway external link management module is used to pre-acquire gateway external link configuration information and set a whitelist for the gateway external links so that the contestant virtual machine can access the specified address based on the gateway external links in the whitelist and send the data generated during the attack and defense exercise to the specified address.

[0095] Optionally, the authorization management module 2300 is specifically used to: prohibit contestant virtual machines from using security testing tools or destroy security testing tools when authorization authentication fails on the authorization authentication server.

[0096] Optionally, the authorization rules may include at least one of the following: usage time, expiration time, and number of uses.

[0097] When the authorization rules include usage time, the authorization management module 2300 is specifically used to: when the time a contestant's virtual machine uses the security testing tool reaches the usage time limit, respond to the contestant's virtual machine's re-initiated authorization authentication request through the authorization authentication server, renew the corresponding authorization certificate, or resend a new authorization certificate to the contestant's virtual machine.

[0098] When the authorization rules include an expiration time, the authorization management module 2300 is specifically used to: prohibit the contestant's virtual machine from using the security testing tool when the time for which the contestant's virtual machine uses the security testing tool expires, or destroy the security testing tool.

[0099] When the authorization rules include the number of uses, the authorization management module 2300 is specifically used to: prohibit the contestant's virtual machine from using the security testing tool or destroy the security testing tool when the number of times the contestant's virtual machine uses the security testing tool exceeds the number of uses.

[0100] It is understood that the network range system 2000 of this application corresponds to the security testing tool anti-theft method provided in the above embodiments. Its specific implementation details and beneficial effects are the same as those of the security testing tool anti-theft method, and will not be repeated here.

[0101] Figure 7 This is a schematic diagram of an electronic device structure provided in one embodiment of this application. Figure 7 As shown, the device includes a memory 1100, a processor 1200, and a communication device 1300. The number of memories 1100 and processors 1200 can be one or more. Figure 7 Taking a memory 1100 and a processor 1200 as an example; the memory 1100 and the processor 1200 in the device can be connected via a bus or other means. Figure 7 Taking the example of a connection between China and Israel via a bus.

[0102] The memory 1100, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the security testing tool anti-theft method provided in any embodiment of this application. The processor 1200 implements the above-mentioned security testing tool anti-theft method by running the software programs, instructions, and modules stored in the memory 1110.

[0103] The memory 1100 may primarily include a program storage area and a data storage area, wherein the program storage area may store the operating system and application programs required for at least one function. Furthermore, the memory 1100 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 1100 may further include memory remotely located relative to the processor 1200, and these remote memories can be connected to the device via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0104] The communication device 1300 is configured to perform information transmission and reception communication under the control of the processor 1200.

[0105] In one embodiment, the communication device 1300 includes a receiver 1310 and a transmitter 1320. The receiver 1310 is a combination of modules or devices for receiving data in an electronic device. The transmitter 1320 is a combination of modules or devices for transmitting data in an electronic device.

[0106] One embodiment of this application also provides a computer-readable storage medium storing computer-executable instructions for performing a method for preventing theft of security testing tools as provided in any embodiment of this application.

[0107] An embodiment of this application also provides a computer program product, including a computer program or computer instructions, characterized in that the computer program or computer instructions are stored in a computer-readable storage medium, the processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium, and the processor executes the computer program or computer instructions, causing the computer device to perform the anti-theft method for security testing tools as provided in any embodiment of this application.

[0108] The system architecture and application scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that as system architectures evolve and new application scenarios emerge, the technical solutions provided in this application are also applicable to similar technical problems.

[0109] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0110] In hardware implementations, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0111] The terms “component,” “module,” “system,” etc., used in this specification are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, or a computer. As illustrated, applications running on computing devices and computing devices can both be components. One or more components may reside in a process or execution thread, and components may be located on a single computer or distributed among two or more computers. Furthermore, these components can be executed from various computer-readable media on which various data structures are stored. Components can communicate, for example, via local or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component between a local system, a distributed system, or a network, such as the Internet interacting with other systems via signals).

[0112] The above description, with reference to the accompanying drawings, illustrates some embodiments of this application, but does not limit the scope of this application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and spirit of this application shall be within the scope of this application.

Claims

1. A security testing tool anti-theft method characterized by, Applied to a cyber range, wherein the cyber range is equipped with an authorization authentication server and a resource leakage prevention system, the method includes: In response to acquiring a security testing tool, a target range identifier and an authorization authentication procedure are set for the security testing tool. The target range identifier is used to mark the data of the security testing tool when transmitting the security testing tool, and the authorization authentication procedure is used to enable the contestant virtual machine to make an authorization authentication request according to the authorization rules. The security testing tool is distributed to the contestant's virtual machine, so that the contestant's virtual machine sends an authorization authentication request to the authorization authentication server according to the authorization rules; The authorization and authentication server receives the authorization and authentication request and sends the corresponding authorization certificate to the contestant virtual machine, so that the contestant virtual machine installs the authorization certificate in the pre-deployed authorization and authentication container and uses the authorized security testing tools to conduct attack and defense drills. The resource leakage prevention system detects the outflow of data transmitted from the contestant's virtual machine to the external network of the target range in real time. If the outflowing data is detected to carry the target range identifier, the outflowing data is intercepted.

2. The method of claim 1, wherein, Setting the target range identifier for the security testing tool includes: The security testing tool is encrypted. During the encryption process, the target range identifier is set for the security testing tool; The step of distributing the security testing tool to the contestant's virtual machine includes: The security testing tool and the corresponding encryption / decryption public key are distributed to the contestant's virtual machine, wherein the encryption / decryption public key is generated when the security testing tool is encrypted.

3. The method of claim 2, wherein, When the encryption process is block encryption, setting the target range identifier for the security testing tool includes: The security testing tool is divided into several data blocks; The data block is divided into blocks and encrypted to obtain an encrypted block corresponding to the data block; The target range identifier is set for each of the encrypted blocks.

4. The method of claim 1, wherein, The method further includes: Pre-obtain gateway external link configuration information; A whitelist is set for the gateway external links so that the contestant virtual machine can access the specified address based on the gateway external links that exist in the whitelist and send the data generated during the attack and defense exercise to the specified address.

5. The method according to any one of claims 1 to 3, characterized in that, The range identification includes at least one of the following: A string of characters randomly generated according to a preset length; A string of characters generated based on the information from the network target range; A string of characters generated based on the current attack and defense exercise information.

6. The method of claim 1, wherein, Receiving the authorization and authentication request through the authorization and authentication server includes: If the authorization authentication server fails to authenticate, the contestant's virtual machine is prohibited from using the security testing tool, or the security testing tool is destroyed.

7. The method according to claim 1 or 6, characterized in that, The authorization rules shall include at least one of the following: usage time, expiration time, and number of uses; If the authorization rules include the usage time, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following steps are also included: When the contestant's virtual machine uses the security testing tool for the time specified in the usage time, the authorization and authentication server responds to the contestant's virtual machine's re-initiated authorization and authentication request by renewing the corresponding authorization certificate or sending a new authorization certificate to the contestant's virtual machine. If the authorization rules include the expiration time, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the method further includes: When the contestant's virtual machine uses the security testing tool for the time it expires, the contestant's virtual machine is prohibited from using the security testing tool, or the security testing tool is destroyed. If the authorization rules include the number of uses, after receiving the authorization authentication request through the authorization authentication server and sending the corresponding authorization certificate to the contestant's virtual machine, the following steps are also included: If the contestant's virtual machine uses the security testing tool more times than the specified number of uses, the contestant's virtual machine will be prohibited from using the security testing tool, or the security testing tool will be destroyed.

8. A network target range system, characterized in that, include The tool management module is used to set a target range identifier and an authorization authentication procedure for the security testing tool in response to obtaining the security testing tool. The target range identifier is used to mark the data of the security testing tool when transmitting the security testing tool, and the authorization authentication procedure is used to enable the contestant virtual machine to make an authorization authentication request according to the authorization rules. The tool distribution module is used to distribute the security testing tool to the contestant virtual machine, so that the contestant virtual machine sends an authorization authentication request to the authorization authentication server according to the authorization rules. The authorization management module is used to receive the authorization authentication request through the authorization authentication server, send the corresponding authorization certificate to the contestant virtual machine, so that the contestant virtual machine installs the authorization certificate in the pre-deployed authorization authentication container and uses the authorized security testing tools to conduct attack and defense drills. The data detection module is used to detect the outflow data transmitted by the contestant's virtual machine to the external network of the target range in real time through the resource leakage prevention system; A data interception module is used to intercept the outflowing data when it is detected that the outflowing data carries the target range identifier.

9. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the method for preventing theft of security testing tools as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by the computer, implement the anti-theft method for security testing tools as described in any one of claims 1 to 7.

11. A computer program product comprising computer programs or computer instructions, characterized in that, The computer program or the computer instruction is stored in a computer readable storage medium, and a processor of a computer device reads the computer program or the computer instruction from the computer readable storage medium. The processor executes the computer program or the computer instruction, so that the computer device executes the anti-theft method of the security testing tool according to any one of claims 1 to 7.