Vulnerability-customizable Network Attack Drill Method, Device, Equipment, Medium and Program Product
By obtaining cyberspace asset information, generating simulated attack paths, determining target assets, and generating corresponding vulnerability simulation tools and exercise solutions, the problem of difficult to determine and simulate network vulnerabilities in the existing technology is solved, and a more realistic and powerful cyber attack exercise is achieved.
Patent Information
- Application Number
- CN202411660435.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-20
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2044-11-20
AI Technical Summary
In existing network offensive and defense exercises, vulnerabilities in computer networks are difficult to determine, especially high-risk vulnerabilities at the bottom such as operating systems, which are difficult to simulate in exercises. Traditional solutions obtaining ‘zero-day vulnerabilities’ are costly and difficult to match multiple exercise scenarios.
Provide a cyberattack exercise method that can be customized for vulnerabilities. By obtaining asset information in the attack cyberspace to be simulated, a candidate simulation attack path is generated, target assets are determined, vulnerability simulation tools and vulnerability exploit tools corresponding to the target assets, simulate vulnerabilities and generate cyberattack exercise plans.
The false ‘cybersecurity hazard’ that appears on any designated attack path is realized, making the cyberattack exercise plan more realistic, and improving the attack intensity and comprehensiveness of the defensive party’s ability test.
Smart Images

Figure CN119276620B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network attack simulation, and particularly to a network attack exercise method, device, computer device, computer-readable storage medium, and computer program product with customizable vulnerabilities. Background Art
[0002] With the development of the Internet and information technology, the security of computer networks has received increasing attention. Currently, network attack and defense exercises are mostly used to test the security of computer systems. However, in actual network attack and defense exercises, it is uncertain which vulnerabilities exist in the computer network, and it is difficult to discover them on-site, especially for high-risk vulnerabilities at the underlying level such as operating systems, which is extremely difficult and there are almost no precedents of on-site discovery.
[0003] In traditional solutions, "zero-day vulnerabilities" are obtained through procurement, which is not only costly but also difficult to match with various exercise scenarios. Summary of the Invention
[0004] Based on this, it is necessary to provide a network attack exercise method, device, computer device, computer-readable storage medium, and computer program product with customizable vulnerabilities that can match various exercise scenarios for the above technical problems.
[0005] In a first aspect, the present application provides a network attack exercise method with customizable vulnerabilities, including:
[0006] Obtain asset information of the network space to be simulated for attack, and generate candidate simulated attack paths according to the asset information;
[0007] Determine target assets according to the candidate simulated attack paths, and generate vulnerability simulation tools and vulnerability exploitation tools corresponding to the target assets; the vulnerability exploitation tools are used for the vulnerabilities simulated by the vulnerability simulation tools;
[0008] When the vulnerability simulation tools are configured in the target assets, generate simulated vulnerabilities through the vulnerability simulation tools, and generate a network attack exercise plan through the simulated vulnerabilities and the vulnerability exploitation tools.
[0009] In one embodiment, the candidate simulated attack paths include at least one of network attack, supply chain attack, social engineering attack, USB flash drive ferry attack, and Internet of Things attack; the determining of the target assets according to the candidate simulated attack paths includes:
[0010] Determine a target simulated attack path according to the candidate simulated attack paths, obtain relevant assets on the target simulated attack path, and use the relevant assets as target assets; the relevant assets include at least one of firewalls, switches, servers, terminals, and isolation devices.
[0011] In one embodiment, the vulnerability simulation tool includes vulnerability simulation software; generating a vulnerability simulation tool corresponding to the target asset and an exploit tool includes:
[0012] When the target asset meets the software installation condition, obtain the operating environment of the target asset and various permissions and data required for simulating vulnerabilities for the target asset, and generate vulnerability simulation software adapted to the operating environment and corresponding to the target asset; the vulnerability simulation software is used to be legally installed on the target asset;
[0013] Generate an exploit tool according to the vulnerability simulation software.
[0014] In one embodiment, the vulnerability simulation software is used to simulate the harmful consequences and exploitation methods of existing vulnerabilities, and the harmful consequences include at least one of being controlled by permissions, data leakage, and software and hardware function failure.
[0015] In one embodiment, the vulnerability simulation tool includes a vulnerability simulation device; the vulnerability simulation device includes a network port and a management port matching the target asset; the network port is used to connect to the network port of the target asset, and the management port is used to connect to the management port of the target asset;
[0016] Generating a vulnerability simulation tool corresponding to the target asset and an exploit tool includes:
[0017] When the target asset does not meet the software installation condition, obtain a vulnerability simulation device; generate an exploit tool according to the vulnerability simulation device.
[0018] In one embodiment, the vulnerability simulation device includes a first network port and a second network port, the first network port is used to connect to the input network port of the target asset, and the second network port is used to connect to the output network port of the target asset.
[0019] In a second aspect, the present application also provides a network attack exercise device, including:
[0020] A path generation module, configured to obtain asset information of the network space to be simulated for attack, and generate candidate simulated attack paths according to the asset information;
[0021] A tool generation module, configured to determine a target asset according to the candidate simulated attack paths, and generate a vulnerability simulation tool and an exploit tool corresponding to the target asset; the exploit tool is used to use the vulnerabilities simulated by the vulnerability simulation tool;
[0022] An exercise plan generation module, configured to generate simulated vulnerabilities through the vulnerability simulation tool when the vulnerability simulation tool is configured in the target asset, and generate a network attack exercise plan through the simulated vulnerabilities and the vulnerability exploitation tool.
[0023] Thirdly, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0024] Obtain asset information of the cyber space to be simulated for attack, and generate candidate simulated attack paths according to the asset information;
[0025] Determine a target asset according to the candidate simulated attack paths, and generate a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the target asset; the vulnerability exploitation tool is used for the vulnerabilities simulated by the vulnerability simulation tool;
[0026] When the vulnerability simulation tool is configured in the target asset, generate simulated vulnerabilities through the vulnerability simulation tool, and generate a network attack exercise plan through the simulated vulnerabilities and the vulnerability exploitation tool.
[0027] Fourthly, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0028] Obtain asset information of the cyber space to be simulated for attack, and generate candidate simulated attack paths according to the asset information;
[0029] Determine a target asset according to the candidate simulated attack paths, and generate a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the target asset; the vulnerability exploitation tool is used for the vulnerabilities simulated by the vulnerability simulation tool;
[0030] When the vulnerability simulation tool is configured in the target asset, generate simulated vulnerabilities through the vulnerability simulation tool, and generate a network attack exercise plan through the simulated vulnerabilities and the vulnerability exploitation tool.
[0031] Fifthly, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:
[0032] Obtain asset information of the cyber space to be simulated for attack, and generate candidate simulated attack paths according to the asset information;
[0033] Determine a target asset according to the candidate simulated attack paths, and generate a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the target asset; the vulnerability exploitation tool is used for the vulnerabilities simulated by the vulnerability simulation tool;
[0034] When the vulnerability simulation tool is configured in the target asset, a simulated vulnerability is generated by the vulnerability simulation tool, and a network attack drill plan is generated through the simulated vulnerability and an exploit tool.
[0035] The above-mentioned customizable network attack drill method, device, computer device, computer-readable storage medium and computer program product obtain asset information of the network space to be simulated for attack, generate candidate simulated attack paths according to the asset information, then determine the target asset according to the candidate simulated attack paths, and then generate a vulnerability simulation tool and an exploit tool corresponding to the target asset. Then, when the vulnerability simulation tool is configured in the target asset, a simulated vulnerability is generated by the vulnerability simulation tool, and a network attack drill plan is generated through the simulated vulnerability and the exploit tool. In the above solution, through the candidate simulated attack paths, the vulnerability simulation tool and the exploit tool, it is possible to create false "cybersecurity risks" that meet the requirements on any specified attack path, so that the obtained network attack drill plan is more realistic, the attack intensity in the network attack drill can be increased, and the comprehensiveness of the test of the defender's ability can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for describing the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0037] Figure 1 It is a schematic flowchart of a customizable network attack drill method in an embodiment;
[0038] Figure 2 It is a schematic flowchart of generating a vulnerability simulation tool and an exploit tool corresponding to a target asset in an embodiment;
[0039] Figure 3 It is a schematic diagram of the installation environment of a vulnerability simulation device in an embodiment;
[0040] Figure 4 It is a structural block diagram of a network attack drill device in an embodiment;
[0041] Figure 5 It is an internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0043] In actual network attack and defense exercises, it is uncertain what vulnerabilities exist in the network system, and it is difficult to dig them out on site, especially high-risk vulnerabilities at the bottom layer such as the operating system, which are extremely difficult and there is almost no precedent for digging them out on site. If "zero-day vulnerabilities" are obtained through procurement, it is not only costly, but also difficult to customize according to the exercise scenario, and it is easy for vulnerabilities to not match. Therefore, current exercises are difficult to simulate high-intensity attack scenarios such as large-scale use of "zero-day vulnerabilities", making it impossible to fully and comprehensively test the network security defense line and the handling capabilities of defenders. Therefore, a network attack and defense actual combat exercise method that can arbitrarily specify attack paths is needed.
[0044] In order to arbitrarily specify an attack path in a network attack and defense exercise, in an exemplary embodiment, Figure 1 As shown, a vulnerability customizable network attack exercise method is provided, comprising the following steps S102 to S106. Among them:
[0045] Step S102, obtaining asset information of the network space to be simulated attacked, and generating candidate simulated attack paths based on the asset information.
[0046] The asset information may refer to the detailed data of various resources and services existing in the cyberspace to be simulated. The assets involved in the asset information may include software assets and hardware assets in the cyberspace. The aforementioned assets may specifically include firewalls, network equipment (switches, routers, etc.), servers, terminals, isolation devices, etc., and may also include workstations, databases, applications, etc.
[0047] Among them, the candidate simulated attack path can be based on the collected asset information, and the attack route or attack method against the specified assets in the current network system can be analyzed and designed from the attacker's perspective. For example, the attack path can be one of the multiple methods such as network attack, supply chain attack, social engineering attack, USB flash drive ferry attack, Internet of Things attack, etc., or any combination of the aforementioned multiple methods.
[0048] Step S104, determining the target asset according to the candidate simulated attack path, generating a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the target asset, wherein the vulnerability exploitation tool is used to exploit the vulnerability simulated by the vulnerability simulation tool.
[0049] Among them, the target assets can refer to the specific resources selected as the attack objects in the candidate simulated attack paths. For example, the candidate simulated attack paths include Attack Path 1, and Attack Path 1 includes Assets A, B, C, D, and E. Suppose Assets A and C are selected as the specific attack objects in Attack Path 1, then Assets A and C are the target assets. Then, vulnerability simulation tools A and C are generated for Assets A and C respectively.
[0050] Among them, the vulnerability simulation tool can be a tool used to create specific simulated security vulnerabilities in the cyberspace; the vulnerability exploitation tool can be used to exploit known security vulnerabilities for attack testing. For example, in an exercise scenario, the vulnerability exploitation tool performs attack actions on the "simulated vulnerabilities" generated by the vulnerability simulation tool.
[0051] Step S106, when the above vulnerability simulation tool is configured in the above target assets, simulated vulnerabilities are generated through the above vulnerability simulation tool, and a network attack exercise plan is generated through the above simulated vulnerabilities and the vulnerability exploitation tool.
[0052] Among them, the simulated vulnerability can refer to a false security vulnerability deliberately created in a controlled environment, such as application vulnerabilities, operating system vulnerabilities, network protocol vulnerabilities, etc. The network attack exercise plan can be a plan including specific attack paths, specific attack objects, and corresponding vulnerability simulation tools and vulnerability exploitation tools for the network space to be simulated for attack.
[0053] Exemplarily, the network space to be simulated for attack can be comprehensively scanned by an automated scanning tool to identify the assets associated with the network space to be simulated for attack and their corresponding attributes. Then, based on the information of the aforementioned assets and attributes, combined with the preset exercise materials, multiple possible attack vectors are constructed as candidate simulated attack paths; then the target assets on each path are determined from the aforementioned candidate simulated attack paths, that is, the assets specifically attacked on each path; then vulnerability simulation tools are generated for the target assets, and corresponding vulnerability exploitation tools are generated according to the vulnerability simulation tools to use the vulnerabilities simulated by the above vulnerability simulation tools through the vulnerability exploitation tools; then the vulnerability simulation tools can be deployed on the target assets, and specific types of simulated vulnerabilities for the target assets are generated on the target assets through the vulnerability simulation tools, and then the vulnerability exploitation tools can be used to initiate attacks. Combining the above processes, a network attack exercise plan is obtained.
[0054] In the above customizable cyber attack drill method, by obtaining the asset information of the cyber space to be simulated for attack, generating candidate simulated attack paths based on the asset information, then determining target assets according to the candidate simulated attack paths, generating vulnerability simulation tools and vulnerability exploitation tools corresponding to the target assets, then, when the vulnerability simulation tools are configured in the target assets, generating simulated vulnerabilities through the above vulnerability simulation tools, and then generating a cyber attack drill plan through the simulated vulnerabilities and the vulnerability exploitation tools; in the above solution, through the candidate simulated attack paths, vulnerability simulation tools and vulnerability exploitation tools, it is possible to create false "cybersecurity risks" that meet the requirements on any specified attack path, and the obtained cyber attack drill plan is more realistic, which can increase the attack intensity in cyber attack drills and improve the comprehensiveness of the inspection of the defender's capabilities.
[0055] In an exemplary embodiment, the above candidate simulated attack paths include at least one of cyber attack, supply chain attack, social engineering attack, USB stick ferry attack, and Internet of Things attack; specifically, determining the target assets according to the above candidate simulated attack paths may include:
[0056] Determining a target simulated attack path according to the above candidate simulated attack paths, obtaining the relevant assets on the above target simulated attack path, and taking the above relevant assets as target assets; the above relevant assets include at least one of a firewall, a switch, a server, a terminal, and an isolation device.
[0057] Among them, a cyber attack may refer to an attack directly launched against a target network or system through a public network, such as a DDoS attack, a Web application attack, a remote code execution, etc.
[0058] Among them, a supply chain attack may refer to an attacker indirectly attacking the end user or organization by infiltrating into a certain link (such as a supplier or a third-party service) in the software supply chain.
[0059] Among them, a social engineering attack may refer to using the personality weaknesses of users (such as curiosity, trust, greed, etc.) to induce victims to disclose sensitive information or perform certain actions.
[0060] Among them, a USB stick ferry attack may refer to physically bringing malware into the target network through a physical means (such as a USB stick or other removable media). For example, an attacker may place a USB stick infected with malware in a public area of the target organization and wait for an unsuspecting employee to insert it into the company computer.
[0061] Among them, an Internet of Things attack may refer to an attack against Internet of Things devices (such as smart cameras, smart home devices, etc.). These devices usually have lower security and are easily used as attack entry points.
[0062] Among them, a firewall can refer to a network security system used to monitor and control the network traffic entering and leaving a cyber space for simulating attacks, preventing unauthorized access. A firewall can be a hardware device or a software application. For example, a hardware firewall can be a dedicated device set outside the network boundary, responsible for monitoring and filtering the network traffic entering and leaving the network. Usually, a hardware firewall is deployed at the edge of the network to protect the internal network from external attacks and unauthorized access. Another example is that a software firewall can be an application installed on a computer or a server, which can be used to monitor and control the network traffic of the installed device.
[0063] Among them, a switch can refer to a network device used to receive and forward data packets and connect different devices within a cyber space for simulating attacks.
[0064] Among them, a server can refer to various computers in a cyber space for simulating attacks that provide databases or other servers.
[0065] Among them, a terminal can refer to a computing device in a cyber space for simulating attacks, such as a desktop computer, a laptop computer, or other mobile devices.
[0066] Among them, an isolation device can refer to a device used to divide a network into different security zones.
[0067] Exemplarily, multiple candidate simulated attack paths can be sent to the terminal of relevant personnel, and a selection operation triggered by the relevant personnel through the terminal can be received. The simulated attack path corresponding to the selection operation is determined as the target simulated attack path. Then, based on the target simulated attack path, key assets on the path are identified, such as firewalls, switches, servers, terminals, and isolation devices, etc. These related assets are used as target assets.
[0068] In this embodiment, by simulating different types of attack paths, including network attacks, supply chain attacks, social engineering attacks, USB drive propagation attacks, and Internet of Things attacks, etc., the target assets are determined. According to the selected attack path, the target simulated attack path is determined and relevant assets are identified. These assets can include firewalls, switches, servers, terminal devices, or isolation devices, etc. In this way, the vulnerability of the system to different types of attacks can be comprehensively evaluated, the security protection ability can be improved, and the attack intensity of the network attack drill plan can be increased.
[0069] In an exemplary embodiment, the above vulnerability simulation tool includes vulnerability simulation software; as Figure 2 shown, the above generation of the vulnerability simulation tool and the vulnerability exploitation tool corresponding to the above target assets specifically can include:
[0070] Step S202, when the above-mentioned target asset meets the software installation conditions, obtain the operating environment of the above-mentioned target asset and various permissions and data required for simulating vulnerabilities for the above-mentioned target asset, and generate a vulnerability simulation software adapted to the above-mentioned operating environment and corresponding to the above-mentioned target asset. The above-mentioned vulnerability simulation software is used to be legally installed on the above-mentioned target asset.
[0071] Step S204, generate a vulnerability exploitation tool according to the above-mentioned vulnerability simulation software.
[0072] Among them, the target asset meeting the software installation conditions may mean that the target asset can install software. For example, assets such as servers and terminals can install software.
[0073] Among them, the operating environment may refer to the operating system and environment in which the target asset runs, as well as information including its version, configuration, etc.
[0074] Exemplarily, through an asset management tool or manual inspection, obtain information such as the operating system type, version, and configuration of the target asset, and confirm whether the target asset supports installing additional software; then, according to the operating environment of the target asset, obtain various permissions and data required for simulating vulnerabilities for the target asset, and then develop and generate a vulnerability simulation software suitable for this environment according to the operating environment and various permissions and data; for example, if the target asset is a server running System A, a vulnerability simulation software specifically designed for the System A environment can be selected; for example, use an open-source project or custom-develop a vulnerability simulation software. In some examples, Python scripts can be used to simulate specific vulnerabilities. Install the obtained vulnerability simulation software on the target asset, configure the vulnerability simulation software to simulate specific types of vulnerabilities, and then, according to the simulated vulnerability types, develop and generate corresponding vulnerability exploitation tools, and ensure that the vulnerability exploitation tools can cooperate with the vulnerability simulation software.
[0075] It should be noted that the installation of the vulnerability simulation software involved in the embodiments of the present application requires user authorization confirmation or full authorization from all parties. The operation of the vulnerability simulation software requires user authorization confirmation or full authorization from all parties. The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the network attack exercise are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0076] In this embodiment, by obtaining the operating environment of the target asset and generating a vulnerability simulation software adapted to this environment, the applicability of the vulnerability simulation tool is improved.
[0077] In an exemplary embodiment, the above-mentioned vulnerability simulation software is used to simulate the harmful consequences and exploitation methods of existing vulnerabilities. The harmful consequences include at least one of being under the control of an attacker, data leakage, and software and hardware function failure. Among them, the exploitation method does not have to be the same as the exploitation details of the existing vulnerability.
[0078] Among them, being under the control of an attacker may mean that the attacker has obtained control of the system and can perform operations beyond its original permissions, such as elevating to administrator permissions. Data leakage may mean that sensitive information is accessed without authorization or exposed to unauthorized individuals. Software and hardware function failure may mean that due to the existence of a vulnerability, the software or hardware cannot work properly. For example, some vulnerabilities may cause the system to blue screen, crash, or become unavailable. The exploitation method not having to be the same as the exploitation details of the existing vulnerability may mean that the simulated exploitation method can be simplified or changed as long as it can effectively convey the risk of the vulnerability. In the embodiment of the present application, the simulated vulnerability is carried out in a controlled environment for the purpose of fully conducting attack drills in the cyberspace and further improving security defense measures.
[0079] In an exemplary embodiment, the above-mentioned vulnerability simulation software remains active in the memory of the above-mentioned target asset.
[0080] Among them, the vulnerability simulation software remaining active in the memory of the target asset may specifically refer to referring to the existing software vulnerability situation, using the memory of the target asset, and hiding itself through methods such as memory resident to avoid being detected by the defense party. For example, a memory vulnerability in the system or application can be utilized, and the vulnerability simulation software can be injected into the memory of the target asset through methods such as memory overflow to achieve continuous residence and execution. Methods such as memory resident may include memory injection, Rootkit technology, dynamic loading, anti-debugging and anti-virtualization, and persistence mechanisms.
[0081] In this embodiment, by keeping the vulnerability simulation software active in the memory of the above-mentioned target asset, the vulnerability simulation software can continuously run and hide itself in the memory of the target asset, preventing it from being detected and cleared by security defense mechanisms or analysis tools, and increasing the concealment and persistence of the simulated attack.
[0082] In an exemplary embodiment, the above-mentioned vulnerability simulation tool includes a vulnerability simulation device; the above-mentioned vulnerability simulation device includes a network port and a management port matching the above-mentioned target asset; the above-mentioned network port is used to connect to the network port of the above-mentioned target asset, and the above-mentioned management port is used to connect to the management port of the above-mentioned target asset; the generation of the vulnerability simulation tool and the vulnerability exploitation tool corresponding to the above-mentioned target asset includes:
[0083] In the case where the above-mentioned target asset does not have software installation conditions, obtain the vulnerability simulation device; generate a vulnerability exploitation tool according to the above-mentioned vulnerability simulation device.
[0084] Among them, when the target asset does not have the condition for software installation, it may mean that software cannot be installed on the target asset. For example, hardware assets such as switches and firewalls cannot install software. Therefore, a vulnerability simulation device can be used to perform vulnerability simulation on the target asset that cannot install software.
[0085] Exemplarily, in the case where the target asset does not have the condition for software installation, obtain a vulnerability simulation device that matches the target asset; then complete the deployment of the vulnerability simulation device for the target asset by connecting the network port of the vulnerability simulation device to the network port of the target asset and connecting the management port of the vulnerability simulation device to the management port of the target asset. Then, develop and generate corresponding vulnerability exploitation tools according to the types of vulnerabilities simulated by the vulnerability simulation device, and ensure that the vulnerability exploitation tools can cooperate with the vulnerability simulation software.
[0086] In this embodiment, in the case where the target asset does not have the condition for software installation, obtain a vulnerability simulation device that matches the target asset. The vulnerability simulation device includes a network port and a management port and can be connected to the target asset to achieve vulnerability simulation for the target asset that does not have the condition for software installation, improving the flexibility and adaptability of the vulnerability simulation tool.
[0087] In an exemplary embodiment, as Figure 3 shown, the target asset can be a hardware asset such as an isolation device. The first end of the target asset is connected to Network 1, and the second end is connected to Network 2. The above-mentioned vulnerability simulation device includes a first network port and a second network port. The first network port is used to connect to the input network port (the first end) of the above-mentioned target asset, and the second network port is used to connect to the output network port (the second end) of the above-mentioned target asset; the management port of the vulnerability simulation device is connected to the management port of the above-mentioned target asset; among them, the vulnerability simulation device can include a development board with multiple network ports.
[0088] It should also be noted that the input network port and the output network port do not represent the actual network transmission methods with Network 1 and Network 2. Both the input network port and the output network port have the function of two-way transmission. In some cases, the input network port can also be used as the output network port, and the output network port can also be used as the input network port. The functions of the network ports of the target asset are set according to actual needs and are not specifically limited here.
[0089] In this embodiment, by connecting the vulnerability simulation device with multiple network ports to the input network port and the output network port of the target asset respectively, that is, the vulnerability simulation device is connected in parallel with the target asset, and then simulating vulnerabilities through the vulnerability simulation device, the effect of the failure of the isolation function of the target asset can be achieved.
[0090] It should be noted that the installation and connection of the vulnerability simulation device involved in the embodiments of the present application require user authorization confirmation or full authorization from all parties. The operation of the vulnerability simulation device also requires user authorization confirmation or full authorization from all parties. The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the network attack exercise are all information and data that have been authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0091] In an exemplary embodiment, the present application further provides a network attack and defense actual combat exercise method for arbitrarily specifying an attack path, which may specifically include the following steps:
[0092] According to the characteristics of software and hardware assets in the cyberspace (asset information of the network space to be simulated for attack), design an attack path (candidate simulated attack path), write vulnerability simulation software, vulnerability simulation devices, and their corresponding vulnerability exploitation tools for the assets (target assets) involved in the attack path. Without the knowledge of the defending party, install the vulnerability simulation software and vulnerability simulation devices on the designated assets to create network security risks such as "zero-day vulnerabilities" and "weak passwords" on the arbitrarily specified attack path, and more realistically simulate high-intensity network attack and defense confrontations, enabling the attacking party to break through the attack target, thereby comprehensively testing the capabilities of the defending party.
[0093] Among them, designing an attack path according to the software and hardware assets in the cyberspace includes, but is not limited to, various methods and their combinations such as network attacks, supply chain attacks, social engineering attacks, USB stick ferry attacks, and Internet of Things attacks; after designing the attack path, sort out the assets involved in the attack path, including but not limited to firewalls, switches, servers, terminals, isolation devices, etc., to point the direction for vulnerability simulation.
[0094] Among them, for hardware assets that can install software independently, such as servers and terminals, vulnerability simulation software is developed: according to the environment such as the operating system on the hardware assets, software specifically used to simulate vulnerabilities that can run on them is developed, simulating vulnerabilities of any operating system, database, browser, and various middleware, and customizing the vulnerability triggering method to achieve consequences such as being controlled by permissions, data leakage, and function failure. By artificially and actively installing the above vulnerability simulation software on the specified assets, the specified assets are made to have specified types of vulnerabilities; vulnerability exploitation tools corresponding to the vulnerability simulation software are developed to achieve vulnerability exploitation. Exemplarily, assuming the vulnerability is a weak password, then as long as the attacker knows this password, they can log in to the system normally, which is a type of vulnerability exploitation; for another example, assuming the vulnerability is a privilege - type vulnerability and there is a specific exp (vulnerability exploitation code) for the vulnerability, sending this exp to the asset where the vulnerability is located can achieve the exploitation of this vulnerability.
[0095] Among them, for hardware assets that cannot install software independently, such as switches and firewalls, vulnerability simulation devices are developed: a development board with a network port and a specified hardware asset management port is selected to develop a vulnerability simulation device. The vulnerability of hardware assets such as switches is simulated on this development board. The network port of the development board is connected to the same local area network as the switch and other hardware, and even shares the same IP address with the switch. Another interface of the development board is connected to the management port of the switch and other hardware assets. At the same time, a vulnerability exploitation tool corresponding to this vulnerability is developed. By exploiting the vulnerability to control this development board, the effect of controlling the switch and other hardware is achieved, thus simulating the consequences of the switch having a vulnerability.
[0096] Among them, the vulnerability simulation software refers to the existing software vulnerability situations and hides itself by means such as memory resident to prevent being detected by the defense party. Among them, the monitoring in the existing technology is carried out through features. When the security software cannot scan the features, it will not be discovered, that is, it cannot be monitored; when the security software does not monitor these scopes, it will also not be monitored. For example, security software usually only monitors the hard disk and does not monitor the memory, so malicious code (vulnerability simulation software) in the memory cannot be monitored.
[0097] Among them, the vulnerability simulation device refers to the existing hardware vulnerability situations, selects a development board with multiple network ports, and connects them to the input and output network ports of hardware such as isolation devices respectively, that is, the development board is in parallel with the isolation device and other hardware. By simulating vulnerabilities on the development board, the effect of the isolation function failure is achieved. Specifically, the vulnerability of the hardware asset is simulated by the vulnerability simulation device. The vulnerability simulation device provides a network entry for vulnerability exploitation. When the vulnerability simulation device is exploited, it is equivalent to the vulnerability simulation device being controlled by the attacker. The attacker can use the vulnerability simulation device to modify the configuration of the isolation device and other hardware assets, thus achieving the effect that there are vulnerabilities on the isolation device and other hardware assets and being exploited.
[0098] For the network attack and defense actual combat exercise method of any of the above-specified attack paths, a vulnerability simulation software, a vulnerability simulation device, and their corresponding vulnerability exploitation tools are developed, and the vulnerability simulation software and the vulnerability simulation device are installed on the specified attack path. By this way of artificially setting vulnerabilities and keeping them secret from the defense side, network security risks such as creating any "zero-day vulnerabilities" and "weak passwords" are realized, and the attacking team uses the vulnerability exploitation tools to conduct attacks, so as to more realistically simulate the high-intensity network attack and defense actual combat confrontation.
[0099] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0100] Based on the same inventive concept, an embodiment of the present application further provides a network attack exercise device for implementing the network attack exercise method with customizable vulnerabilities described above. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the network attack exercise device provided below can refer to the limitations on the network attack exercise method with customizable vulnerabilities in the above text, and will not be repeated here.
[0101] In an exemplary embodiment, as Figure 4 shown, a network attack exercise device 900 is provided, including: a path generation module 901, a tool generation module 902, and an exercise plan generation module 903, where:
[0102] The path generation module 901 is configured to obtain asset information of the network space to be simulated for attack, and generate candidate simulated attack paths according to the above asset information.
[0103] The tool generation module 902 is configured to determine target assets according to the above candidate simulated attack paths, and generate a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the above target assets; the above vulnerability exploitation tool is used to use the vulnerabilities simulated by the above vulnerability simulation tool.
[0104] The exercise plan generation module 903 is configured to generate simulated vulnerabilities through the vulnerability simulation tool when the vulnerability simulation tool is configured in the target asset, and generate a network attack exercise plan through the simulated vulnerabilities and the vulnerability exploitation tool.
[0105] In an exemplary embodiment, the candidate simulated attack paths at least include one of network attack, supply chain attack, social engineering attack, USB flash drive ferry attack, and Internet of Things attack; the tool generation module 902 is further configured to determine a target simulated attack path according to the candidate simulated attack paths, obtain the relevant assets on the target simulated attack path, and use the relevant assets as target assets; the relevant assets at least include one of a firewall, a switch, a server, a terminal, and an isolation device.
[0106] In an exemplary embodiment, the vulnerability simulation tool includes vulnerability simulation software; the exercise plan generation module 903 is further configured to obtain the operating environment of the target asset when the target asset meets the software installation condition, and generate vulnerability simulation software adapted to the operating environment and corresponding to the target asset; the vulnerability simulation software is used to be legally installed on the target asset; generate a vulnerability exploitation tool according to the vulnerability simulation tool.
[0107] In an exemplary embodiment, the vulnerability simulation tool includes a vulnerability simulation device; the vulnerability simulation device includes a network port and a management port matching the target asset; the network port is used to connect to the network port of the target asset, and the management port is used to connect to the management port of the target asset; the exercise plan generation module 903 is further configured to obtain the vulnerability simulation device when the target asset does not meet the software installation condition; generate a vulnerability exploitation tool according to the vulnerability simulation device.
[0108] Each module in the above network attack exercise device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0109] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 5As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for a vulnerability-customizable network attack exercise.
[0110] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0111] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0112] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0113] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0114] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0115] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0116] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A vulnerability customizable network attack exercise method, characterized in that: The method comprises: Acquire asset information of the network space to be simulated attacked, and generate candidate simulated attack paths according to the asset information; Determine the target asset according to the candidate simulated attack path, generate a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the target asset; the vulnerability exploitation tool is used to use the vulnerability simulated by the vulnerability simulation tool; the vulnerability exploitation tool is further used to perform an attack action against the vulnerability simulated by the vulnerability simulation tool; In the case where the vulnerability simulation tool is configured in the target asset, a simulated vulnerability is generated by the vulnerability simulation tool, and a network attack exercise plan is generated by the simulated vulnerability and the vulnerability exploitation tool.
2. The method according to claim 1, characterized in that The candidate simulated attack paths include at least one of network attacks, supply chain attacks, social engineering attacks, USB ferry attacks, and Internet of Things attacks; and determining the target assets according to the candidate simulated attack paths includes: Determine a target simulated attack path according to the candidate simulated attack path, obtain relevant assets on the target simulated attack path, and use the relevant assets as target assets; the relevant assets include at least one of a firewall, a switch, a server, a terminal, and an isolation device.
3. The method according to claim 1, characterized in that The vulnerability simulation tool includes vulnerability simulation software; the generation of the vulnerability simulation tool and vulnerability exploitation tool corresponding to the target asset includes: When the target asset meets the software installation conditions, the operating environment of the target asset and various permissions and data required for simulating vulnerabilities of the target asset are obtained, and vulnerability simulation software corresponding to the target asset and adapted to the operating environment is generated; the vulnerability simulation software is used to be legally installed on the target asset; A vulnerability exploitation tool is generated according to the vulnerability simulation software.
4. The method according to claim 3, characterized in that The vulnerability simulation software is used to simulate the harmful consequences and exploitation methods of existing vulnerabilities, and the harmful consequences include at least one of permission control, data leakage, and software and hardware function failure.
5. The method according to claim 1, characterized in that The vulnerability simulation tool includes a vulnerability simulation device; the vulnerability simulation device includes a network port and a management port matching the target asset; the network port is used to connect to the network port of the target asset, and the management port is used to connect to the management port of the target asset; The generating of the vulnerability simulation tool and the vulnerability exploitation tool corresponding to the target asset comprises: When the target asset does not have the software installation conditions, obtaining a vulnerability simulation device; A vulnerability exploitation tool is generated according to the vulnerability simulation device.
6. The method according to claim 5, characterized in that The vulnerability simulation device includes a first network port and a second network port, the first network port is used to connect to the input network port of the target asset, and the second network port is used to connect to the output network port of the target asset.
7. A network attack exercise device, characterized in that: The device comprises: A path generation module, used to obtain asset information of the network space to be simulated and attack, and generate candidate simulated attack paths according to the asset information; A tool generation module, used to determine a target asset according to the candidate simulated attack path, and generate a vulnerability simulation tool and a vulnerability exploitation tool corresponding to the target asset; the vulnerability exploitation tool is used to use the vulnerability simulated by the vulnerability simulation tool; the vulnerability exploitation tool is further used to execute an attack action against the vulnerability simulated by the vulnerability simulation tool; The exercise plan generation module is used to generate a simulated vulnerability through the vulnerability simulation tool when the vulnerability simulation tool is configured in the target asset, and to generate a network attack exercise plan through the simulated vulnerability and the vulnerability exploitation tool.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Dynamic honey spot placing method and device
CN117176452A
Vulnerability simulation method and device
CN117610018A