Simulation deduction method and device applied to network target range, equipment and medium

By acquiring network connectivity and vulnerability information of the target environment, drawing network topology diagrams, matching attack paths, and eliminating non-intrusive paths, the resource consumption and flexibility issues of network range simulation and simulation are resolved, enabling fast and effective security simulation.

CN119316172BActive Publication Date: 2025-12-05INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410578504.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-10
Publication Date
2025-12-05
Estimated Expiration
2044-05-10

AI Technical Summary

Technical Problem

Existing network range simulations require the construction of simulation systems, which consume a lot of resources and are not flexible enough to quickly adapt to the upgrades and changes in the real network environment.

Method used

By acquiring network connectivity and vulnerability information of the target environment, a network topology diagram is drawn, potential attack paths are matched, non-intrusive paths are eliminated, and a simplified access path is displayed, enabling rapid simulation and deduction.

Benefits of technology

Without building a simulation system, it can quickly discover potential security vulnerabilities, improve simulation efficiency, reduce costs, and flexibly respond to changes in the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119316172B_ABST
    Figure CN119316172B_ABST
Patent Text Reader

Abstract

The disclosure provides a simulation deduction method applied to a network target range, which can be applied to the technical field of information security. The method comprises the following steps: obtaining access information, wherein the access information comprises information of a starting network asset and a target network asset; obtaining network connection information of all network assets in a target environment, wherein the network connection information comprises connection and disconnection conditions of one network asset with other network assets, and a connection direction when one network asset is connected with another network asset; then taking the starting network asset as a starting point and the target network asset as an ending point, and drawing a network topology graph from the starting network asset to the target network asset according to the network connection information of all network assets in the target environment, so as to obtain a network access path. The disclosure also provides a simulation deduction device, equipment, storage medium and program product arranged in the network target range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of information security technology and can be used in the financial field or other fields. More specifically, it relates to a simulation and deduction method, apparatus, equipment, medium and program product applied to network test ranges. Background Technology

[0002] With the continuous development of information technology, the impact of potential hacker attacks and security incidents on business systems is becoming increasingly significant. Organizations typically improve their network environment's ability to withstand various cyberattacks by conducting attack and defense simulations of different security incidents. Because cyberattacks are destructive and pose potential security risks to real network environments, simulations are usually conducted in cyber ranges through attack and defense exercises.

[0003] Currently, when conducting simulation exercises in network test ranges, in order to achieve realistic and reliable simulation effects and discover potential security vulnerabilities, it is often necessary to first build a simulation system corresponding to the real network environment in the network test range, and then conduct attack and defense drills in the simulation system. This simulation method requires a lot of resources to build the simulation system, has a long preparation time, and if the real network environment is upgraded, the simulation system needs to be upgraded simultaneously, increasing the cost of building the simulation system and making the simulation exercises inflexible. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a simulation and deduction method, apparatus, device, medium and program product for network ranges, which can quickly simulate and deduce the security attack and defense performance of the target environment without building a simulation system by means of real network data collected from the target environment.

[0005] A first aspect of this disclosure provides a simulation and deduction method applied to a network test range. The method includes: acquiring access information to a target environment, the access information including information about a starting network asset and a target network asset, wherein the starting network asset and the target network asset are network assets in the target environment; acquiring network connectivity information for all network assets in the target environment, wherein the network connectivity information includes the connectivity status of one network asset with other network assets, and the connection direction when one network asset is connected to another network asset; and then, using the starting network asset as the starting point and the target network asset as the ending point, drawing a network topology map from the starting network asset to the target network asset based on the network connectivity information of all network assets in the target environment to obtain a network access path.

[0006] According to embodiments of this disclosure, the method further includes: obtaining a vulnerability information table, which at least records the communication addresses of hosts with vulnerabilities in the target environment; matching the communication addresses of all network assets in the network access path with the communication addresses of hosts with vulnerabilities in the vulnerability information table; wherein the network connectivity information also includes the communication addresses of network assets; if the match is successful, determining that the access information is malicious; otherwise, determining that the access information is not malicious.

[0007] According to embodiments of this disclosure, the method further includes: if a match is successful, determining the network assets, the starting network asset, and the target network asset that match the vulnerability information table in the network access path as reserved nodes; traversing each reserved node except for the starting network asset and the target network asset, wherein, while traversing each reserved node, the connection path between the reserved node and its nearest other reserved node is selected from the network access path along the upstream and downstream directions respectively to obtain a reserved path; removing all paths other than the reserved paths from the network access path to obtain a simplified access path; and displaying the simplified access path.

[0008] According to embodiments of this disclosure, the data in the vulnerability information table is extracted from host monitoring data and vulnerability scanning data of the target environment. The host monitoring data is obtained by real-time monitoring of each host in the target environment. The vulnerability scanning data is obtained by performing vulnerability scans on each host in the target environment.

[0009] According to embodiments of this disclosure, the network connectivity information of all network assets in the target environment is extracted from network scan data and network traffic data, wherein the network scan data is data obtained by scanning the network assets in the target environment; and the network traffic data is data extracted from the access traffic of the target environment.

[0010] According to embodiments of this disclosure, obtaining network connectivity information of all network assets in the target environment includes: obtaining a network asset table, which records communication attribute information of all network assets in the target environment, including the communication address and liveness status information of the network assets; and obtaining a network connectivity table, wherein the network connectivity table records the connection relationships and connection directions between different network assets in the target environment.

[0011] According to an embodiment of this disclosure, the step of drawing a network topology map from the starting network asset to the target network asset based on the network connectivity information of all network assets in the target environment, with the starting network asset as the starting point and the target network asset as the ending point, to obtain a network access path includes: starting from the starting network asset, traversing the network assets in the target environment according to the network connectivity information, wherein: for each network asset traversed, the network asset is connected to other network assets that are connected to the network asset and are located downstream of the network asset in the connection direction.

[0012] A second aspect of this disclosure provides a simulation and deduction device set up in a network test range. The device includes: a first acquisition module, a second acquisition module, and a path analysis module. The first acquisition module is used to acquire access information to a target environment, the access information including information about a starting network asset and a target network asset, wherein the starting network asset and the target network asset are network assets in the target environment. The second acquisition module is used to acquire network connectivity information of all network assets in the target environment, wherein the network connectivity information includes the connectivity status of one network asset with other network assets, and the connection direction when one network asset is connected to another network asset. The path analysis module is used to draw a network topology map from the starting network asset to the target network asset, based on the network connectivity information of all network assets in the target environment, with the starting network asset as the starting point and the target network asset as the ending point, to obtain a network access path.

[0013] According to embodiments of this disclosure, the apparatus further includes an intelligent deduction module. The intelligent deduction module is configured to: obtain a vulnerability information table, which at least records the communication addresses of hosts with vulnerabilities in the target environment; match the communication addresses of all network assets in the network access path with the communication addresses of hosts with vulnerabilities in the vulnerability information table; wherein the network connectivity information also includes the communication addresses of network assets; if a match is successful, determine that the access information is malicious; otherwise, determine that the access information is not malicious.

[0014] According to embodiments of this disclosure, the apparatus further includes a visualization module. The intelligent deduction module is further configured to: if a match is successful, determine the network assets, the starting network asset, and the target network asset in the network access path that match the vulnerability information table as reserved nodes; traverse each reserved node except for the starting network asset and the target network asset, wherein, while traversing each reserved node, the connection path between the reserved node and its nearest other reserved node is selected from the network access path along the upstream and downstream directions respectively to obtain a reserved path; and remove all paths other than the reserved paths from the network access path to obtain a simplified access path. The visualization module is also configured to display the simplified access path.

[0015] A third aspect of this disclosure provides an electronic device. The electronic device includes one or more processors and a memory. The memory stores one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the aforementioned simulation and deduction method applied to a network target range.

[0016] A fourth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the above-described simulation and deduction method applied to a network target range.

[0017] A fifth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described simulation and deduction method applied to a network target range. Attached Figure Description

[0018] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0019] Figure 1 The illustration schematically depicts an application scenario of a simulation and deduction method, apparatus, device, medium, and program product applied to a network range according to embodiments of the present disclosure;

[0020] Figure 2 A flowchart illustrating a simulation and deduction method applied to a network test range according to an embodiment of the present disclosure is shown schematically.

[0021] Figure 3 This illustration schematically shows the processing flow after obtaining the network access path in a simulation and deduction method applied to a network range according to another embodiment of the present disclosure;

[0022] Figure 4A block diagram schematically illustrates a simulation and deduction apparatus set up in a cyber range according to an embodiment of the present disclosure;

[0023] Figure 5 This schematically illustrates a framework diagram of a simulation and deduction apparatus set up in a cyber range according to another embodiment of the present disclosure;

[0024] Figure 6 Schematic illustration Figure 5 The simulation simulation device set up in the network range is shown in the simulation flowchart.

[0025] Figure 7 Schematic illustration Figure 5 A schematic diagram of the data acquisition module in the device shown.

[0026] Figure 8 Schematic illustration Figure 5 A framework diagram of the data analysis module in the device shown;

[0027] Figure 9 Schematic illustration Figure 5 The diagram shows the framework of the deduction module in the device shown; and

[0028] Figure 10 A block diagram schematically illustrates an electronic device suitable for implementing a simulation and deduction method for a cyber range according to embodiments of the present disclosure. Detailed Implementation

[0029] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0030] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0031] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0032] This disclosure provides a simulation and deduction method, apparatus, device, medium, and program product for network range testing. According to embodiments of this disclosure, given network connectivity information for all network assets in the target environment, for any access information, based on the connectivity status and direction of each network asset with other network assets in the connectivity information, other downstream network assets connected to each network asset are searched and connected until the target network asset is reached. This forms the network access path corresponding to the access information. With the network access path, it is only necessary to analyze whether there are vulnerabilities or exploitable points in the network assets within the path to determine whether the access information is offensive, where the vulnerabilities are, and how to protect against them. In this way, potential dangers in the target environment can be quickly identified without building a simulation system or posing a risk to the real network environment, allowing for targeted protective measures.

[0033] Figure 1 The illustration schematically depicts an application scenario of a simulation and deduction method, apparatus, device, medium, and program product applied to a network range according to embodiments of the present disclosure.

[0034] like Figure 1 As shown, application scenario 100 according to this embodiment may include target environment 10, terminal device 101, network 102, and server 103. Network 102 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc. Server 103 is a hardware component of the network range and can provide related services in the network range.

[0035] The target environment 10 is equipped with various data acquisition devices. These data acquisition devices can communicate with the server 103 via network 102. For example, the data acquisition devices can transmit various types of data collected from the target environment 10 to the server 103 via network 102. The server 103 processes this data to obtain various data required for simulating and deducing the target environment 10, such as network connectivity information, vulnerability information tables, host information tables, or network asset tables.

[0036] Terminal device 101 can communicate with server 103 via network 102. For example, terminal device 101 can upload collected access information to server 103, thereby triggering server 103 to perform simulation. Correspondingly, server 103 can also feed back the simulation results, such as network access paths, to terminal device 101 for viewing by the user of terminal device 101.

[0037] It should be noted that the simulation and deduction method applied to a network range provided in this disclosure embodiment can generally be executed by server 103. Correspondingly, the simulation and deduction device, equipment, medium, and program product set up in a network range provided in this disclosure embodiment can generally be set up in server 103. The simulation and deduction method provided in this disclosure embodiment can also be executed by a server or server cluster that is different from server 103 and can communicate with terminal device 101 and / or server 103. Correspondingly, the simulation and deduction device, equipment, medium, and program product set up in a network range provided in this disclosure embodiment can also be set up in a server or server cluster that is different from server 103 and can communicate with terminal device 101 and / or server 103.

[0038] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0039] It should be noted that the simulation and deduction methods, devices, equipment, media and program products for network test ranges provided in the embodiments of this disclosure can be used in the financial field, or in any field other than the financial field. This disclosure does not limit the application field.

[0040] The following will be based on Figure 1 The described application scenarios, through Figures 2-3 The simulation and deduction method applied to network test ranges according to the embodiments of this disclosure will be described in detail.

[0041] Figure 2 A flowchart illustrating a simulation and deduction method applied to a network range according to an embodiment of the present disclosure is shown schematically.

[0042] like Figure 2 As shown, the simulation and deduction method applied to the network target range according to this embodiment may include operations S201 to S203.

[0043] In operation S201, access information for the target environment 10 is obtained, including information about the originating network assets and the target network assets. The originating network assets and the target network assets are network assets within the target environment 10.

[0044] Specifically, the access information must include at least the origin and destination points of the access. Therefore, the information regarding the originating and destination network assets refers to the address information, device identifier, or device name of the origin and destination points indicated in the access information.

[0045] In operation S202, network connectivity information of all network assets in target environment 10 is obtained. The network connectivity information includes the connectivity status of one network asset with other network assets, and the connection direction when one network asset is connected to another network asset.

[0046] In some embodiments, such as Figure 1 As shown, when data is collected from the target environment 10, and network scan data and network traffic data of the target environment 10 are collected, network connectivity information of all network assets in the target environment 10 can be extracted from the network scan data and network traffic data.

[0047] Network scan data is data obtained by scanning network assets in target environment 10. For example, network scans can be performed on network assets in target environment 10 periodically or irregularly to obtain information such as IP addresses, port data, address liveness status, connectivity relationships between addresses, or upstream and downstream connectivity directions of network assets.

[0048] Network traffic data is data extracted from the access traffic of target environment 10. For example, it is possible to intercept traffic data accessing target environment 10 in real time and extract information such as the sending address, destination IP address and port, and the direction of address access from the traffic.

[0049] Network traffic data offers better real-time performance compared to network scan data. Therefore, network scan data can be used to verify or update network traffic data, reducing the likelihood that changes or updates within the target environment 1 0 may not be reflected in the network scan data in a timely manner.

[0050] Compared to network traffic data, network scan data offers more comprehensive coverage. Network communication information in network traffic data is affected by external access patterns, making it uncertain and often uneven. This can easily lead to network traffic data failing to cover the connectivity information of all assets in the target environment 10.

[0051] Therefore, by combining network scan data and network traffic data of target environment 10, network connectivity information of all network assets in target environment 10 can be extracted. This can ensure that the extracted network connectivity information has comprehensive coverage to a large extent, and can also improve the real-time performance of the extracted network connectivity information to a certain extent.

[0052] In operation S203, starting from the initial network asset and ending at the target network asset, a network topology diagram from the initial network asset to the target network asset is drawn based on the network connectivity information of all network assets in the target environment 10, so as to obtain the network access path.

[0053] During the drawing process, starting with the initial network asset, the network assets in the target environment 10 are traversed based on network connectivity information until the target network asset is reached. Each time a network asset is encountered, it is connected to other network assets that are connected to it and located downstream in the connection direction. The traversal order is as follows: first, the initial network asset is traversed, connecting it to other network assets that are connected to it and can be located downstream. Next, the other network assets connected to the initial network asset are traversed. This process continues along the connection path, traversing the network assets at the end of each connection until the target network asset is reached.

[0054] As can be seen, when performing simulations in the target environment 10, this embodiment can simulate the security protection effect of the target environment 10 based on the network connectivity information of all network assets in the target environment 10, without affecting the operation of the target environment 10 and without needing to build a simulation system. This allows for the discovery of potential weaknesses and facilitates timely repair. Furthermore, as long as the network connectivity information of the target environment is sufficiently accurate, real-time, and comprehensive through information collection and monitoring, the simulation of the target environment 10 can closely match the actual production system. This avoids the time and effort required to build a simulation system and does not pose any risk to the real system, effectively improving the efficiency of the simulation.

[0055] Figure 3 The illustration schematically shows the processing flow after obtaining the network access path in a simulation and deduction method applied to a network range according to another embodiment of the present disclosure.

[0056] like Figure 3 As shown, the simulation and deduction method applied to the network target range according to this embodiment may include operations S301 to S309 after operations S201 to S203.

[0057] During operation S301, the vulnerability information table is obtained. The vulnerability information table records at least the communication addresses (e.g., IP addresses) of the hosts in the target environment 10 that have vulnerabilities.

[0058] In operation S302, when the network connectivity information also includes the communication addresses of network assets, the communication addresses of all network assets in the network access path are matched with the communication addresses of hosts with vulnerabilities in the vulnerability information table.

[0059] In operation S303, determine whether the match in operation S302 was successful. If not, proceed to operation S304; if yes, proceed to operation S305.

[0060] If an S304 operation fails to match, it indicates that the network assets in the network access path are not vulnerable and there are no points that can be exploited. Therefore, it can be determined that the access information is not malicious.

[0061] If a match is found when operating S305, it is determined that the access information is malicious.

[0062] In one embodiment, when it is determined in operation S305 that the access information is malicious, the network access path can be output to the terminal device 101. At the same time, the information of network assets that successfully match the vulnerability information table in the network access path can also be output to the terminal device 101 to help the user analyze the specific threat content in the access information so as to select a targeted protection strategy.

[0063] In another embodiment, the network access path can be simplified by operating S306 to S309 and then output to the terminal device 101.

[0064] Specifically, in operation S306, network assets, starting network assets, and target network assets that successfully match the vulnerability information table in the network access path are all identified as reserved nodes.

[0065] In operation S307, each reserved node except for the starting network asset and the target network asset is traversed. When traversing each reserved node, the connection path between the reserved node and its nearest other reserved node is selected from the network access path along the upstream and downstream directions, respectively, to obtain the reserved path.

[0066] In operation S308, all paths except those reserved are removed from the network access paths to obtain a simplified access path.

[0067] Then, operate S309 to display the simplified access path.

[0068] By performing further analysis and processing through steps S306 to S308, paths connecting to all vulnerable hosts can be filtered from the network access paths, and branches not connecting to vulnerable hosts can be eliminated. This results in a streamlined access path with reduced redundancy. Providing this streamlined access path to users allows for more accurate and efficient analysis of weaknesses in the target environment, leading to more precise security protection.

[0069] Based on the simulation and deduction methods applied to network test ranges described in the above embodiments, this disclosure also provides a simulation and deduction device set up in a network test range. The following will be combined with... Figure 4 The device is described in detail.

[0070] Figure 4The diagram illustrates a structural block diagram of a simulation and deduction device 400 set up in a cyber range according to an embodiment of the present disclosure.

[0071] like Figure 4 As shown, according to some embodiments of this disclosure, the device 400 may include a first acquisition module 410, a second acquisition module 420, and a path analysis module 430. According to other embodiments of this disclosure, the device 400 may further include an intelligent deduction module 440 and / or a visualization module 450.

[0072] The first acquisition module 410 is used to acquire access information to the target environment. The access information includes information about the starting network asset and the target network asset, wherein the starting network asset and the target network asset are network assets in the target environment. In one embodiment, the first acquisition module 410 can perform the operation S201 described above.

[0073] The second acquisition module 420 is used to acquire network connectivity information of all network assets in the target environment 10. The network connectivity information includes the connectivity status of one network asset with other network assets, and the connection direction when one network asset is connected to another network asset. In one embodiment, the second acquisition module 420 can perform the operation S202 described above.

[0074] The path analysis module 430 is used to draw a network topology map from the starting network asset to the target network asset, based on the network connectivity information of all network assets in the target environment 10, to obtain the network access path. In one embodiment, the path analysis module 430 can perform the operation S203 described above.

[0075] The intelligent deduction module 440 is used to: obtain a vulnerability information table, which records at least the communication addresses of vulnerable hosts in the target environment 10; match the communication addresses of all network assets in the network access path with the communication addresses of vulnerable hosts in the vulnerability information table; wherein, network connectivity information also includes the communication addresses of network assets; if the match is successful, determine that the access information is malicious; otherwise, determine that the access information is not malicious. In one embodiment, the intelligent deduction module 440 can execute operations S301 to S305 as described above.

[0076] The intelligent deduction module 440 is further configured to: if a match is successful, identify the network assets, starting network assets, and target network assets in the network access path that match the vulnerability information table as reserved nodes; traverse each reserved node except for the starting network asset and the target network asset, wherein, while traversing each reserved node, the connection path between the reserved node and its nearest other reserved node is selected from the network access path along the upstream and downstream directions respectively to obtain a reserved path; and remove all paths other than the reserved paths from the network access path to obtain a simplified access path. In one embodiment, the intelligent deduction module 440 can also perform operations S307 to S308 as described above.

[0077] The visualization module 450 is used to display a simplified access path. In one embodiment, the visualization module 450 can perform the operation S309 described above.

[0078] The device 400 can perform reference Figures 2-3 The specific methods are described in the previous text and will not be repeated here.

[0079] The following is passed Figures 5-9 A simulation and deduction device 500 configured in a cyber range, according to another embodiment of this disclosure, will be described. It should be understood that the following description is exemplary and does not constitute a limitation of this disclosure.

[0080] Figure 5 A schematic diagram of a simulation and deduction apparatus 500 set up in a cyber range according to another embodiment of the present disclosure is shown.

[0081] like Figure 5 As shown, the device 500 includes a data acquisition module 501, a data analysis module 502, a deduction module 503, a visualization module 450, and an asset database module 505.

[0082] Figure 6 Schematic illustration Figure 5 The simulation simulation device 500 set up in the network target range is shown as a simulation flowchart.

[0083] like Figure 6As shown, the simulation process of each module in device 500 is as follows: First, the data acquisition module 501 collects environmental information of the target environment 10 and temporarily stores it (e.g., in the system asset library); then, the data analysis module 502 parses the data according to the data analysis strategy and reconstructs it into the data required for simulation (e.g., network channel information, vulnerability information table, etc. mentioned above), and stores it in the asset library module 505. After the data preparation is completed, the simulation module 503 simulates the network access path in the target environment 10 based on the input access information. This process can be repeated according to the simulation requirements of the data. Finally, the visualization module 450 displays the simulation results. The specific functions of each module are as follows.

[0084] Data acquisition module 501: It has the ability to actively or passively collect data information from the target environment 10. For example, it can automatically collect data results from acquisition devices deployed in the target environment 10 according to set parameters, and can preprocess the collected information through pre-configuration, or directly import the processed data through standardized template tables.

[0085] Data analysis module 502: It can analyze the data collected by data acquisition module 501 according to the configuration strategy, mark the analysis results, reconstruct the data through the marking results to form the data required in the inference process, and store it in asset library module 505.

[0086] The deduction module 503 can determine the starting network asset and the target network asset of the access based on the starting point and target point information in the input access information. Then, it calls the information in the network asset table and network connectivity table in the asset library module 505 to automatically generate the network access path. By associating the host, vulnerability and other information in the vulnerability information table in the asset library module 505, it automatically finds whether there are any exploitable vulnerability points in the network access path, and performs access path deduction in this way.

[0087] Visualization module 450: This module uses information visualization technology to display the simulation results of the deduction module 503, and allows control of the deduction process through commands such as triggering, pausing, and replaying. For example, visualization module 450 can be used to display the process of drawing network access paths.

[0088] Asset repository module 505: This is a data storage unit that provides temporary storage for data collected by data acquisition module 501, database storage services for data analyzed and reconstructed by data analysis module 502, and relevant data asset data for the deduction process of deduction module 503.

[0089] Figure 7 Schematic illustration Figure 5 The diagram shows the framework of the data acquisition module 501 in the device 500.

[0090] like Figure 7 As shown, the data acquisition module 501 may include a data acquisition submodule 511 and a data update submodule 512.

[0091] The data acquisition submodule 511 can interconnect with various data collection devices set up in the target environment 10 through standardized data input / output interfaces. These data collection devices include, but are not limited to, network scanning devices, traffic mirroring devices, and host monitoring devices. The data acquisition submodule 511 can receive data collected by these devices or directly receive templated, pre-organized asset information tables. The received data can be temporarily stored in a temporary data table in the asset database module 505, and the collected information can be pre-processed using pre-configured acquisition parameters, such as merging and deleting duplicate data.

[0092] Data update submodule 512: If the data acquisition submodule 511 collects data from the target environment 10 by connecting to an external device, the data update submodule 512 can automatically retrieve the latest data from the external device periodically according to the set time parameters and mark the data status as updated. If a full update is required, the information acquisition module 511 is called to perform full data acquisition.

[0093] Figure 8 Schematic illustration Figure 5 A framework diagram of the data analysis module 502 in the device 500 shown.

[0094] like Figure 8 As shown, the data analysis module 502 may include a structure analysis module 521 and an asset construction module 522. When the structure analysis module 521 detects data in a temporary data table in the asset repository module 505, it analyzes the data in the temporary data table and marks the data. An example of the analysis and marking process for different types of data is shown below.

[0095] For network traffic data, extract the sending address, destination IP address, and port from the traffic, and mark the access direction of the address.

[0096] For host monitoring data, extract the host name, corresponding IP address and port, mark the host's liveness status, and simultaneously extract the operating system version, the names and related version numbers of installed middleware, application software, etc. (if any).

[0097] For network scan data, extract network IP addresses and port data, and mark the liveness status of the addresses. Since network scan data is usually not real-time, while host monitoring data can be collected in real time, the IP address information extracted from the network scan data can be compared with the host monitoring data. Live IP addresses from the host monitoring data are retained, while inactive IP addresses are deleted. Additionally, live IP addresses not recorded in the host monitoring data are retained. In this way, the information in the network scan data can be updated using the host monitoring data.

[0098] For vulnerability scanning data, extract vulnerability names, host IP addresses, and hostnames, and mark the correspondence between vulnerabilities and hosts. Similarly, since vulnerability scanning data is usually not real-time, the IP address information extracted from the vulnerability scanning data can be compared with the IP address information in the host monitoring data, retaining the IP addresses that match the host monitoring data and their corresponding vulnerability information. Furthermore, vulnerability scanning data can also be compared with network scanning data, retaining consistent IP addresses and related data, and deleting inconsistent information. This allows for comparison and verification of information from data collected from different devices or in different ways, improving the accuracy and timeliness of the information.

[0099] The asset construction module 522 is used to take the data and marking results extracted by the structure analysis module 521 as input information, and automatically generate various formal asset database tables required for the simulation process in the target environment 10, including but not limited to: host information table, network asset table, vulnerability information table, and network connectivity table. The asset construction module 522 can update the corresponding data in the various formal tables by updating the data markings made by the structure analysis module 521.

[0100] The host information table records the hostname, corresponding IP address and port, liveness status, operating system version, installed middleware, application software and other information of all hosts in the target environment 10.

[0101] The network asset table records the communication attribute information of all network assets in the target environment 10, including the communication address and liveness status information of the network assets.

[0102] The vulnerability information table records the communication addresses of vulnerable hosts in the target environment 10, such as IP addresses and ports, and may also include the correspondence between vulnerability information and hosts. The data in the vulnerability information table can be extracted from host monitoring data and vulnerability scanning data of the target environment 10.

[0103] The network connectivity table records information such as the connection relationships and connection directions between different network assets in the target environment 10.

[0104] Figure 9 Schematic illustration Figure 5 The diagram shows the framework of the deduction module 503 in the device 500.

[0105] like Figure 9 As shown, the deduction module 503 may include a path analysis module 430 and an intelligent deduction module 440.

[0106] The path analysis module 430 receives externally input access information. This access information includes information about the starting point and target point in the network simulation (such as IP addresses). Based on this information, the starting network asset and the target network asset can be located from the network asset table. Then, based on the information in the network connectivity table, a network topology diagram from the starting network asset to the target network asset can be automatically drawn, thereby generating a network access path.

[0107] The intelligent deduction module 440 can extract information on all host nodes in the network access path derived by the path analysis module 430, and match the host node information (such as IP address) with the vulnerability information table in the asset database module 505. If the host information in the network access path is matched in the vulnerability information table, it is determined that this node can be exploited. Then, the process is transferred to subsequent nodes through this node, following the above judgment pattern until the target network asset is reached. If there are branches in the network access path for which the host information of a node is not found in the vulnerability information table, the branch can be deleted to simplify the network access path.

[0108] The simulation conducted in this way, by using information data actually collected from the target environment 10, can closely match the actual production system without posing any risk to the real system.

[0109] Moreover, compared with the simulation system construction method in related technologies, the simulation of the present disclosure can improve the efficiency of the simulation. When the target environment 10 changes, the change can be quickly captured by collecting information data, so that the simulation effect can be adapted to the changed target environment 10, which has considerable flexibility.

[0110] Furthermore, compared to paper-based or script-based simulations that abstract or idealize the target environment 10, the simulation in this embodiment describes the target environment 10 based on real data collected from the target environment 10. This greatly avoids the drawback of reducing the reference value of the simulation results due to the simulation process deviating from the actual system.

[0111] As can be seen, the embodiments of this disclosure can quickly generate various data required for simulation based on data collected from the target environment 10, effectively simulate and extrapolate access behavior in the target environment, reduce simulation preparation time, and generate and display intuitive and visual network access paths.

[0112] According to the embodiments of this disclosure, intelligent analysis can be performed in conjunction with the real environment of the target environment 10, and network simulation can be automatically completed. This can improve the efficiency of the simulation, reduce the manual input in the simulation process, and provide services such as system protection capability testing and penetration simulation for all parties without affecting the real network environment.

[0113] According to embodiments of this disclosure, any and multiple modules among the first acquisition module 410, second acquisition module 420, path analysis module 430, intelligent deduction module 440, visualization module 450, data acquisition module 501, data analysis module 502, deduction module 503, and asset database module 505 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the first acquisition module 410, the second acquisition module 420, the path analysis module 430, the intelligent deduction module 440, the visualization module 450, the data acquisition module 501, the data analysis module 502, the deduction module 503, and the asset database module 505 can be at least partially implemented as hardware circuits, such as field-programmable gate arrays (FPGAs), programmable logic arrays (PLAs), systems-on-a-chip, systems-on-a-substrate, systems-on-package, application-specific integrated circuits (ASICs), or any other reasonable means of integrating or packaging circuits, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the first acquisition module 410, the second acquisition module 420, the path analysis module 430, the intelligent deduction module 440, the visualization module 450, the data acquisition module 501, the data analysis module 502, the deduction module 503, and the asset database module 505 can be at least partially implemented as computer program modules, which can perform corresponding functions when the computer program module is run.

[0114] Figure 10 A block diagram schematically illustrates an electronic device suitable for implementing a simulation and deduction method for a cyber range according to embodiments of the present disclosure.

[0115] like Figure 10As shown, an electronic device 1000 according to an embodiment of the present disclosure includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage portion 1008 into a random access memory (RAM) 1003. The processor 1001 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1001 may also include onboard memory for caching purposes. The processor 1001 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0116] RAM 1003 stores various programs and data required for the operation of electronic device 1000. Processor 1001, ROM 1002, and RAM 1003 are interconnected via bus 1004. Processor 1001 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 1002 and / or RAM 1003. It should be noted that the programs may also be stored in one or more memories other than ROM 1002 and RAM 1003. Processor 1001 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0117] According to embodiments of this disclosure, the electronic device 1000 may further include an input / output (I / O) interface 1005, which is also connected to a bus 1004. The electronic device 1000 may also include one or more of the following components connected to the I / O interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1010 as needed so that computer programs read from it can be installed into the storage section 1008 as needed.

[0118] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0119] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 1002 and / or RAM 1003 and / or one or more memories other than ROM 1002 and RAM 1003 described above.

[0120] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the simulation and deduction method for network ranges provided in embodiments of this disclosure.

[0121] When the computer program is executed by the processor 1001, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0122] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 1009, and / or installed from a removable medium 1011. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0123] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 1009, and / or installed from removable medium 1011. When the computer program is executed by processor 1001, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0124] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0125] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0126] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0127] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A simulation deduction method applied to a network target range, comprising: obtaining access information of a target environment, the access information comprising information of a starting network asset and a target network asset, wherein the starting network asset and the target network asset are network assets in the target environment; obtaining network connectivity information of all network assets in the target environment, wherein the network connectivity information comprises connectivity of one network asset to other network assets and connectivity direction when one network asset is connected to another network asset; and drawing a network topology graph from the starting network asset to the target network asset according to the network connectivity information of all network assets in the target environment, to obtain a network access path.

2. The method of claim 1, wherein, The method further comprises: obtaining a vulnerability information table, the vulnerability information table recording at least a communication address of a host with a vulnerability in the target environment; matching the communication address of all network assets in the network access path with the communication address of the host with the vulnerability in the vulnerability information table, wherein the network connectivity information further comprises the communication address of the network asset; if the matching is successful, determining that the access information is attackable; otherwise, determining that the access information is not attackable.

3. The method of claim 2, wherein, The method further comprises: if the matching is successful, determining the network asset in the network access path that matches the vulnerability information table, the starting network asset and the target network asset as reserved nodes; traversing each reserved node except the starting network asset and the target network asset, wherein when traversing each reserved node, a connection path between the reserved node and another reserved node closest to the reserved node is filtered out in an upstream direction and a downstream direction from the network access path respectively, to obtain a reserved path; eliminating all paths except the reserved paths from the network access path, to obtain a simplified access path; and displaying the simplified access path.

4. The method of claim 2, wherein, Data in the vulnerability information table is extracted from host monitoring data and vulnerability scanning data of the target environment, wherein the host monitoring data is obtained by real-time monitoring of each host in the target environment; the vulnerability scanning data is obtained by vulnerability scanning of each host in the target environment.

5. The method of claim 1, wherein, The network connectivity information of all network assets in the target environment is extracted from network scanning data and network traffic data, wherein the network scanning data is obtained by network scanning of network assets in the target environment; the network traffic data is extracted from access traffic of the target environment.

6. The method of claim 1 or 5, wherein, The obtaining of the network connectivity information of all network assets in the target environment comprises: obtaining a network asset table, the network asset table recording communication attribute information of all network assets in the target environment, the communication attribute information comprising a communication address and survival state information of the network asset; and obtain a network on-off table, wherein the network on-off table records connection relationships and connection directions between different network assets in the target environment.

7. The method of claim 1, wherein, drawing a network topology graph from the starting network asset to the target network asset according to the network on-off information of all network assets in the target environment, to obtain a network access path. starting from the starting network asset, traversing network assets in the target environment according to the network on-off information, wherein: each time a network asset is traversed, the network asset and other network assets connected to the network asset and located downstream of the network asset in the connection direction are connected.

8. A simulation and deduction device arranged in a network target range, comprising: a first obtaining module configured to obtain access information of a target environment, the access information comprising information of a starting network asset and a target network asset, wherein the starting network asset and the target network asset are network assets in the target environment; a second obtaining module configured to obtain network on-off information of all network assets in the target environment, wherein the network on-off information comprises on-off conditions of one network asset with respect to other network assets, and a connection direction when one network asset is connected to another network asset; and a path analysis module configured to draw a network topology graph from the starting network asset to the target network asset according to the network on-off information of all network assets in the target environment, to obtain a network access path.

9. An electronic device, comprising: one or more processors; a storage device configured to store one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement steps of the method according to any one of claims 1-7.

10. A computer readable storage medium having stored thereon a computer program, wherein, The computer program is executed by the processor to implement steps of the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Network target range simulation method and device for industrial control system and medium

    CN117371153A

  • Asset discovery using established network connections of known assets

    US20190281072A1