A network target range internal network flow protocol monitoring system and method
Patent Information
- Application Number
- CN202311044824.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-18
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2043-08-18
AI Technical Summary
但一个环境中外部网络IP资源只有有限的256个,这种方式会大量消耗有限的外部网络IP
[0027]Beneficial effects: Compared with the prior art, the present invention has the following advantages: 1. By using the internal network, the test range platform and internal network nodes of different network segments and traffic actuators are connected, saving limited external network IP resources; 2. The test range platform can directly obtain the actual traffic information received on the nodes, making the traffic monitoring results in the scenario more realistic, and through a graphical display of the results, it can intuitively reflect the overall traffic situation in the current scenario and the traffic information on different nodes.
Smart Images

Figure CN117135088B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a traffic protocol monitoring system and method, and more particularly to a network range intranet traffic protocol monitoring system and method, belonging to the fields of network security and computer software. Background Technology
[0002] A cyber range is a testing platform that uses virtualization technology to simulate a real cyberspace attack and defense combat environment, supporting combat capability research and weapon equipment verification. To achieve the above objectives, range users will simulate various actual cyber attack and defense operations during actual training or verification.
[0003] Currently, traffic generation functionality in network testbeds can flexibly generate the traffic required in the environment. The architecture for traffic generation is generally as follows: Figure 1 As shown, one or more traffic executors are established in each scenario. These traffic executors then establish network connections with the target nodes. When the test range platform issues a traffic task, the traffic executor directly sends traffic to the target node. Because the test range platform needs to be accessed externally, this service needs to be deployed on an external network (management network). Since the test range platform needs to issue tasks to the traffic executors, the traffic executors also need to be allocated external network IPs. The traffic executors then establish internal network interfaces to connect with nodes on the internal network (scenario business network) within the scenario. However, an environment only has a limited number of external network IP resources (256), and this approach will consume a large number of these limited external network IPs.
[0004] In addition, since the test range platform cannot directly access the nodes in the intranet of the scenario, the current traffic monitoring in the environment generally focuses on monitoring the traffic issued by the traffic actuator, and cannot effectively count the quantity and type of traffic received on the actual target node. Summary of the Invention
[0005] Purpose of the invention: In view of the problems existing in the prior art, the purpose of this invention is to provide a network range intranet traffic protocol monitoring system and method that can save external network IP resources and can acquire the traffic status on the node in real time and upload it to the range platform for analysis.
[0006] Technical solution: To achieve the above-mentioned objectives, the present invention adopts the following technical solution:
[0007] The network range intranet traffic protocol monitoring system of the present invention includes: a range platform, a traffic actuator, a target node, and a central router;
[0008] The target range platform is used to manage traffic files, configure traffic tasks, and send traffic task instructions from the intranet to the traffic executor through the central router, as well as receive and statistically process the traffic information reported by each target node.
[0009] The traffic actuator is connected to the central router via an internal network IP address, and indirectly connected to the target node and the test range platform in the scenario via the central router. It is used to receive and execute traffic tasks from the test range platform and send traffic to the target node according to the configuration.
[0010] The central router is used to connect networks of different network segments in the scenario;
[0011] The target node is used to receive traffic sent by the traffic executor and to monitor the traffic information received by the node in real time through a traffic monitoring service deployed on the target node.
[0012] Furthermore, the test range platform connects to a central router in a different network segment of the intranet by creating one or more intranet ports, thereby enabling the test range platform to communicate with intranet nodes in the scenario via the intranet.
[0013] Furthermore, the test range platform records the internal network IP used by the central router for connection and determines whether there is a network port in the same network segment as the IP. If not, it adds a network port in the same network segment to establish a connection to the central router.
[0014] Furthermore, the traffic monitoring service deployed on the target node is used to monitor all actual traffic information and traffic rate of the target node, parse the information, obtain the protocol information contained in different packets, record the number of different protocol information, and report this information to the test range platform through the central router.
[0015] Furthermore, after receiving the traffic information reported by the nodes, the range platform integrates the rate information of different nodes in the scene and displays the bandwidth rate of different nodes and / or the entire scene in the form of charts on the page, in order to determine whether the traffic bandwidth needs to be increased or decreased in the entire scene and / or specific nodes.
[0016] And / or, the test range platform aggregates the protocol information of traffic from different nodes and displays the percentage of traffic from different protocols in the scenario in the form of charts, in order to determine whether the protocol type of traffic needs to be expanded in the scenario and / or whether the bandwidth of specific protocol traffic needs to be increased or decreased.
[0017] Based on the same inventive concept, this invention also provides a method for monitoring intranet traffic protocols in a network test range, comprising the following steps:
[0018] Configure a central router in the user-initiated network range scenario to connect different network segments within the scenario;
[0019] In the scenario, the traffic actuator creates an internal network port, configures an internal network IP, and connects to the central router. The traffic actuator is indirectly connected to the target node and the test range platform in the scenario through the central router. It is used to receive and execute traffic tasks from the test range platform and send traffic to the target node according to the configuration.
[0020] The test range platform manages traffic files, configures traffic tasks, and sends traffic task instructions from the intranet to the traffic executor through the central router.
[0021] The target node receives the traffic sent by the traffic executor and monitors the traffic information received by the node in real time through the traffic monitoring service deployed on the target node, and reports the traffic information to the test range platform.
[0022] The test range platform receives and statistically analyzes the traffic information reported by each target node.
[0023] Furthermore, the scenario is a virtual network environment generated by constructing a network topology in the target range environment, in which traffic attacks and simulated behaviors in real scenarios can be simulated.
[0024] Furthermore, the central router is a regular router. If a router that can connect all network segments in the scenario already exists, then that router will be used as the central router, and a separate router will not be configured as the central router.
[0025] Furthermore, the test range platform records the internal network IP used by the central router for external connections, and determines whether there is a network port in the same network segment as the IP. If not, it adds a network port in the same network segment to connect to the central router, and synchronously records the association information between the network port and the scenario.
[0026] Furthermore, the traffic monitoring service is used to monitor all actual traffic information and traffic rates received by the node, parse the information, obtain the protocol information contained in different packets, record the quantity of different protocol information, and report this information to the test range platform through the central router. The test range platform integrates the rate information of different nodes in the scenario and displays the bandwidth rate of different nodes and / or the entire scenario in a chart to determine whether the traffic bandwidth of the entire scenario and / or a specific node needs to be increased or decreased. And / or, the test range platform also summarizes the protocol information of traffic from different nodes and displays the percentage of different protocol traffic in the scenario in the form of a chart to determine whether the protocol type of traffic needs to be expanded and / or whether the bandwidth of a specific protocol needs to be increased or decreased.
[0027] Beneficial effects: Compared with the prior art, the present invention has the following advantages: 1. By using the internal network, the test range platform and internal network nodes of different network segments and traffic actuators are connected, saving limited external network IP resources; 2. The test range platform can directly obtain the actual traffic information received on the nodes, making the traffic monitoring results in the scenario more realistic, and through a graphical display of the results, it can intuitively reflect the overall traffic situation in the current scenario and the traffic information on different nodes. Attached Figure Description
[0028] Figure 1 This is a schematic diagram of existing technology;
[0029] Figure 2 This is a schematic diagram of an embodiment of the present invention. Detailed Implementation
[0030] The technical solution of the present invention will now be clearly and completely described in conjunction with the accompanying drawings and specific embodiments.
[0031] This invention discloses a network range intranet traffic protocol monitoring system and method, as shown in the attached figure. Figure 2 As shown, by deploying a central router in each scenario to connect nodes on different network segments within the scenario, the test range platform establishes an intranet connection with the central router through its intranet port, thus enabling communication between the test range platform and the intranet nodes in the scenario. Simultaneously, when each node in the scenario starts up, it initializes a traffic monitoring service to obtain real-time traffic information and upload it to the test range platform. This allows the test range platform to issue traffic tasks via the intranet and simultaneously receive traffic transmission results via the intranet.
[0032] The network range intranet traffic protocol monitoring system of the present invention includes: a range platform, a traffic actuator, a target node, and a central router;
[0033] The target range platform is used to manage traffic files, configure traffic tasks, and send traffic task instructions from the intranet to the traffic executor through the central router, as well as receive and statistically process the traffic information reported by each target node.
[0034] The traffic actuator is connected to the central router via an internal network IP address, and indirectly connected to the target node and the test range platform in the scenario via the central router. It is used to receive and execute traffic tasks from the test range platform and send traffic to the target node according to the configuration.
[0035] The central router is used to connect networks of different network segments in the scenario;
[0036] The target node is used to receive traffic sent by the traffic executor and to monitor the traffic information received by the node in real time through a traffic monitoring service deployed on the target node.
[0037] Furthermore, the test range platform connects to a central router in a different network segment of the intranet by creating one or more intranet ports, thereby enabling the test range platform to communicate with intranet nodes in the scenario via the intranet.
[0038] In particular, if all networks in the scenario are already connected through existing routers, there is no need to configure a separate central router; the existing router in the scenario can be used directly as the central router.
[0039] Furthermore, the test range platform records the internal network IP used by the central router for connection and determines whether there is a network port in the same network segment as the IP. If not, it adds a network port in the same network segment to establish a connection to the central router.
[0040] Furthermore, the traffic monitoring service deployed on the target node is used to monitor all actual traffic information and traffic rate of the target node, parse the information, obtain the protocol information contained in different packets, record the number of different protocol information, and report this information to the test range platform through the central router.
[0041] Furthermore, after receiving the traffic information reported by the nodes, the range platform integrates the rate information of different nodes in the scene and displays the bandwidth rate of different nodes and / or the entire scene in the form of charts on the page, in order to determine whether the traffic bandwidth needs to be increased or decreased in the entire scene and / or specific nodes.
[0042] And / or, the test range platform aggregates the protocol information of traffic from different nodes and displays the percentage of traffic from different protocols in the scenario in the form of charts, in order to determine whether the protocol type of traffic needs to be expanded in the scenario and / or whether the bandwidth of specific protocol traffic needs to be increased or decreased.
[0043] Based on the same inventive concept, this invention also provides a method for monitoring intranet traffic protocols in a network test range, comprising the following steps:
[0044] Configure a central router in the user-initiated network range scenario to connect different network segments within the scenario;
[0045] In the scenario, the traffic actuator creates an internal network port, configures an internal network IP, and connects to the central router. The traffic actuator is indirectly connected to the target node and the test range platform in the scenario through the central router. It is used to receive and execute traffic tasks from the test range platform and send traffic to the target node according to the configuration.
[0046] The test range platform manages traffic files, configures traffic tasks, and sends traffic task instructions from the intranet to the traffic executor through the central router.
[0047] The target node receives the traffic sent by the traffic executor and monitors the traffic information received by the node in real time through the traffic monitoring service deployed on the target node, and reports the traffic information to the test range platform.
[0048] The test range platform receives and statistically analyzes the traffic information reported by each target node.
[0049] Furthermore, the scenario is a virtual network environment generated by constructing a network topology in the target range environment, in which traffic attacks and simulated behaviors in real scenarios can be simulated.
[0050] Furthermore, the central router is a regular router. If a router that can connect all network segments in the scenario already exists, then that router will be used as the central router, and a separate router will not be configured as the central router.
[0051] Furthermore, the test range platform records the internal network IP used by the central router for external connections, and determines whether there is a network port in the same network segment as the IP. If not, it adds a network port in the same network segment to connect to the central router, and synchronously records the association information between the network port and the scenario.
[0052] Furthermore, the target node is a virtual machine launched in the scenario, used to receive traffic sent by the traffic executor. When each node starts, a traffic monitoring service is deployed on the node via Cloud-init. Based on the cross-platform nature of Cloud-init, the traffic monitoring service can be deployed on virtual machines of different systems.
[0053] Furthermore, the traffic monitoring service is used to monitor all actual traffic information and traffic rates received by the node, parse the information, obtain the protocol information contained in different packets, record the quantity of different protocol information, and report this information to the test range platform through the central router. The test range platform integrates the rate information of different nodes in the scenario and displays the bandwidth rate of different nodes and / or the entire scenario in the form of a curve graph on the page, which is used to determine whether the traffic bandwidth of the entire scenario and / or a specific node needs to be increased or decreased. And / or, the test range platform also summarizes the protocol information of traffic from different nodes and displays the percentage of different protocol traffic in the scenario in the form of a bar chart, which is used to determine whether the protocol type of traffic needs to be expanded and / or whether the bandwidth of a specific protocol needs to be increased or decreased.
Claims
1. A network range intranet traffic protocol monitoring system, characterized in that, include: Target platform, flow actuator, target node, and central router; The target range platform is used to manage traffic files, configure traffic tasks, and send traffic task instructions from the intranet to the traffic executor through the central router, as well as receive and statistically process the traffic information reported by each target node. The traffic actuator is connected to the central router via an internal network IP address, and indirectly connected to the target node and the test range platform in the scenario via the central router. It is used to receive and execute traffic tasks from the test range platform and send traffic to the target node according to the configuration. The central router is used to connect networks of different network segments in the scenario; The target node is used to receive traffic sent by the traffic executor and to monitor the traffic information received by the node in real time through a traffic monitoring service deployed on the target node.
2. The network range intranet traffic protocol monitoring system according to claim 1, characterized in that, The test range platform connects to a central router in a different network segment by creating one or more intranet ports, enabling the test range platform to communicate with intranet nodes in the scenario via the intranet.
3. The network range intranet traffic protocol monitoring system according to claim 1, characterized in that, The test range platform records the internal network IP used by the central router for connection and determines whether there is a network port in the same network segment as the IP. If not, it adds a network port in the same network segment to establish a connection to the central router.
4. The network range intranet traffic protocol monitoring system according to claim 1, characterized in that, The traffic monitoring service deployed on the target node is used to monitor all actual traffic information and traffic rate of the target node, parse the information, obtain the protocol information contained in different packets, record the number of different protocol information, and report this information to the test range platform through the central router.
5. The network range intranet traffic protocol monitoring system according to claim 1, characterized in that, After receiving the traffic information reported by the nodes, the range platform integrates the rate information of different nodes in the scene and displays the bandwidth rate of different nodes and / or the entire scene in the form of charts on the page, in order to determine whether the traffic bandwidth needs to be increased or decreased in the entire scene and / or specific nodes. And / or, the test range platform aggregates the protocol information of traffic from different nodes and displays the percentage of traffic from different protocols in the scenario in the form of charts, in order to determine whether the protocol type of traffic needs to be expanded in the scenario and / or whether the bandwidth of specific protocol traffic needs to be increased or decreased.
6. A method for monitoring intranet traffic protocols in a network test range, characterized in that, Includes the following steps: Configure a central router in the user-initiated network range scenario to connect different network segments within the scenario; In the scenario, the traffic actuator creates an internal network port, configures an internal network IP, and connects to the central router. The traffic actuator is indirectly connected to the target node and the test range platform in the scenario through the central router. It is used to receive and execute traffic tasks from the test range platform and send traffic to the target node according to the configuration. The test range platform manages traffic files, configures traffic tasks, and sends traffic task instructions from the intranet to the traffic executor through the central router. The target node receives the traffic sent by the traffic executor and monitors the traffic information received by the node in real time through the traffic monitoring service deployed on the target node, and reports the traffic information to the test range platform. The test range platform receives and statistically analyzes the traffic information reported by each target node.
7. The network range intranet traffic protocol monitoring method according to claim 6, characterized in that, The scenario described is a virtual network environment generated by constructing a network topology within a test range environment. This environment can simulate traffic attacks and simulated behaviors in real-world scenarios.
8. The network range intranet traffic protocol monitoring method according to claim 6, characterized in that, The central router is a regular router. If a router that can connect all network segments in the scenario already exists, then that router will be used as the central router, and a separate router will not be configured as the central router.
9. The network range intranet traffic protocol monitoring method according to claim 6, characterized in that, The test range platform records the internal network IP used by the central router for external connections and determines whether there is a network port in the same network segment as the IP. If not, it adds a network port in the same network segment to connect to the central router and synchronously records the association information between the network port and the scenario.
10. The network range intranet traffic protocol monitoring method according to claim 6, characterized in that, The traffic monitoring service is used to monitor all actual traffic information and traffic rates received by the node, parse the information, obtain the protocol information contained in different packets, record the quantity of different protocol information, and report this information to the test range platform through the central router. The test range platform integrates the rate information of different nodes in the scenario and displays the bandwidth rate of different nodes and / or the entire scenario in a chart to determine whether the traffic bandwidth of the entire scenario and / or a specific node needs to be increased or decreased. And / or, the test range platform also summarizes the protocol information of traffic from different nodes and displays the percentage of different protocol traffic in the scenario in the form of a chart to determine whether the protocol type of traffic needs to be expanded and / or whether the bandwidth of a specific protocol needs to be increased or decreased.
Citation Information
Patent Citations
Route configuration method and device of dedicated cloud host
CN104506668A
Network target range probe downloading and acquisition reporting method and system
CN116074223A