Method, device and drill system for constructing network security competition auxiliary training model
By building a network security competition assisted training model and using the data in the network security database and historical offensive and defense database for training, the problems of lack of dynamics and challenges, lack of adaptability, and lack of simulation complex network security challenges in the existing technology are solved, efficient personalized training and strategy optimization are achieved, and the practical level and adaptability of network security protection are improved.
Patent Information
- Application Number
- CN202510272255.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-10
AI Technical Summary
The lack of dynamic and challenging nature, lack of adaptability, and lack of simulation in the existing network security competitions has led to a decrease in practicality and challenges in training and competitions, insufficient adaptability, and the inability to comprehensively evaluate the participants' comprehensive capabilities and innovation and optimization of defense systems.
By building a network security competition assisted training model, the original data in the network security database and historical offensive and defense database are used for preprocessing, the label sample training set is obtained, the secondary classification and model training is performed, the attack module and defense module are trained, the model is optimized through hyperparameter tuning and cross-entropy loss function, and the trained model is used to score attack behavior, defensive behavior and vulnerability level on the system vulnerability information.
It has realized the simulation of advanced network threats and policy optimization, provided personalized training, improved defenders' immediate response and policy deployment capabilities, and enhanced the practical level and adaptability of network security protection.
Smart Images

Figure CN119761225B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, specifically to a method, device, and drill system for constructing an auxiliary training model for network security competitions. Background Art
[0002] With the rapid development of information technology, network security issues have become increasingly prominent. In order to make the network security attack and defense range closer to the real attack and defense scenarios, and at the same time to more efficiently select and cultivate attack and defense talents, the AWD competition system is used for the attack and defense training of security teams and important national network security competitions. Traditional methods may be more focused on the depth of technology and are suitable for in-depth exploration of specific skills, but they may lack a comprehensive consideration of comprehensive capabilities, adaptability, and teamwork. In contrast, although the AWD mode has higher requirements in terms of resources and organization, it can more comprehensively exercise and evaluate the actual combat capabilities of contestants and is closer to the actual needs of network security work.
[0003] The disadvantages of the existing technology mainly include the following aspects:
[0004] Lack of dynamics and challenges: Attack and defense exercises without AI participation may be relatively static, making it difficult to simulate the constantly changing strategies and techniques of attackers in the real world, reducing the practicality and challenges of training and competitions. Due to the lack of an AI-driven adaptive opponent, the participating teams face a relatively static and predictable threat model, which limits their ability to cultivate the ability to respond to flexible and changeable strategies in real network battles. Therefore, it is difficult for participants to hone their skills in high-intensity and high-interaction real confrontations, reducing the opportunity to discover and repair system security vulnerabilities, and affecting the understanding and prevention of modern attack means such as advanced persistent threats (APTs). In addition, the fixed challenge mode may also inhibit the research and development of innovative strategies and technologies, causing the disconnect between competition education and actual combat, and reducing the overall skill improvement effect and contribution to industry progress.
[0005] Lack of adaptability: It is difficult for both the attacking and defending sides to simulate the dynamically changing threats and defense requirements in the real network environment. The attack strategies are easy to predict, and the defensive measures may be solidified, which is insufficient to deal with complex and changeable attack means. This not only weakens the ability training of participants in strategic planning, immediate response, and technological innovation, but also may lead to insufficient awareness of the latest security threats. In addition, the fixed attack and defense mode limits the comprehensive evaluation of the comprehensive capabilities of contestants and affects the efficiency of discovering and cultivating top security talents. Therefore, the lack of adaptability will limit the fairness, challenges, and practicality of the competition, and is not conducive to the innovation and optimization of the network security defense system.
[0006] Lack of simulation of complex cybersecurity challenges: It limits the value of its role as a practical exercise platform. This not only restricts the contestants' preparation for real-world challenges such as advanced persistent threats and zero-day attacks, but also may lead to the neglect of cultivating strategic depth, technological innovation, and emergency response capabilities. The lack of complex scenario simulation makes the competition more like a superficial application of theoretical knowledge rather than a profound contest of skills and wisdom. Moreover, it affects the true test of the resilience of the defense system and the flexibility of security strategies, making it difficult to comprehensively evaluate the effectiveness of defense solutions. Therefore, such a competition environment is not conducive to cultivating high-level professionals capable of dealing with future security threats, nor can it provide strong support for the iterative upgrade of cybersecurity protection strategies. Summary of the Invention
[0007] In this embodiment, a method, a system, an electronic device, and a storage medium for constructing an auxiliary training model for a cybersecurity competition are provided to solve the problems of lack of dynamics and challenges, lack of adaptability, and lack of simulation of complex cybersecurity challenges in simulated cybersecurity confrontation or competition in related technologies.
[0008] In a first aspect, an embodiment of the present invention provides a method for constructing an auxiliary training model for a cybersecurity competition. The method for constructing the auxiliary training model for a cybersecurity competition includes:
[0009] Obtain raw data from a cybersecurity database and a historical attack and defense database, and preprocess the raw data to obtain a labeled sample training set, where the samples include positive samples and negative samples;
[0010] Perform secondary classification on the positive samples and the negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0011] Use at least one set of subclass positive samples and subclass negative samples to train the model. Among them, the subclass positive samples are used to train the corresponding submodels and scoring modules configured for the attack module of the model, and the subclass negative samples are used to train the corresponding submodels configured for the defense module of the model;
[0012] Find the best parameter combination through a hyperparameter tuning algorithm, train and optimize the model through a cross-entropy loss function, and use the iteratively trained model as an auxiliary training model;
[0013] Obtain the vulnerability information of both systems, and use the trained auxiliary training model to give attack behaviors, defense behaviors, and vulnerability level scores for the system vulnerability information.
[0014] Optionally, obtaining raw data from a cybersecurity database and a historical attack and defense database, and preprocessing the raw data to obtain a labeled sample training set includes:
[0015] Obtain the original data, which includes vulnerability sets, attack vectors, internal logs, service configurations, traffic monitoring, vulnerability data, historical cases, and defense strategies;
[0016] Clean the original data to obtain processed samples;
[0017] Classify and label the processed samples to obtain positive samples and negative samples.
[0018] Optionally, perform secondary classification on the positive samples and the negative samples to obtain at least one set of subclass positive samples and subclass negative samples, including:
[0019] Obtain the sub-model information configured by the model attack module, model defense module, and scoring module, as well as the required training sample data;
[0020] According to the sub-model information and the required sample data, perform secondary classification on the positive samples and negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0021] Use the subclass positive samples and subclass negative samples to train the sub-models configured by the model attack module, scoring module, and model defense module.
[0022] Optionally, the sub-model configured by the attack module includes a generative adversarial network, a classification model, a reinforcement learning model, and a sequence model; the sub-model configured by the defense module includes an intrusion detection and prevention system model, a deep learning model, a rule engine combined with a machine learning model, and a graph neural network.
[0023] Optionally, obtain the vulnerability information of both systems, and use the trained auxiliary training model to give attack behaviors for the system vulnerability information, including:
[0024] Obtain the vulnerability information and the level score of each vulnerability, and conduct in-depth analysis on each vulnerability to extract key features;
[0025] Use the trained generative adversarial network to generate attack vectors according to the input vulnerability key features;
[0026] Generate attack behaviors by passing the generated attack vectors through penetration testing tools.
[0027] Optionally, obtain the vulnerability information of both systems, and use the trained auxiliary training model to give defense behaviors for the system vulnerability information, including:
[0028] Obtain the vulnerability information and the level score of each vulnerability;
[0029] Update the signature library and rule set of the intrusion detection and prevention system model based on the latest vulnerability information, and conduct defense according to the vulnerability information.
[0030] Optionally, obtain the system vulnerability information of both parties, and use the trained auxiliary training model to give a vulnerability level score for the system vulnerability information, including:
[0031] Use a vulnerability scanning tool to obtain the system vulnerabilities of the adversarial party, analyze the vulnerabilities, obtain the influencing factors of each vulnerability, and set a basic weight for each influencing factor of each vulnerability;
[0032] Obtain the importance index score of the vulnerability according to the calculation formula of each basic weight;
[0033] Rank the importance levels of the vulnerabilities based on the importance index scores.
[0034] Compared with the prior art, the beneficial effects of the method for constructing a network security competition auxiliary training model of the present invention are as follows:
[0035] By training the attack module and the defense module of the auxiliary training model, the model can learn relevant knowledge of network security and competition offense and defense, and give attack suggestions, automatic attacks, active defenses, and vulnerability scoring based on the system vulnerabilities of the other party or its own party. By constructing the auxiliary training model, it is possible to simulate advanced network threats and strategy optimization and conduct personalized training for individuals. The auxiliary training model, on the attack side, deeply learns past attack cases through deep learning, and dynamically generates high-fidelity advanced threat scenarios according to training needs, testing the immediate response and strategy deployment capabilities of defenders; on the defense side, the auxiliary training model analyzes competition data in real time, provides immediate feedback to participants, accurately identifies defense vulnerabilities while optimizing defense strategies to achieve strategy customization. This personalized intensive training enables defenders to grow rapidly in a combat-like environment, learn to anticipate and effectively resist various network attacks that may be encountered in the future, thereby greatly improving the actual combat level and adaptability of network security protection.
[0036] In a second aspect, an embodiment of the present invention provides a device for constructing a network security competition auxiliary training model, including:
[0037] A preprocessing module for obtaining raw data from a network security database and a historical attack and defense database, and preprocessing the raw data to obtain a labeled sample training set, where the samples include positive samples and negative samples;
[0038] A secondary classification module for secondary classification of the positive samples and the negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0039] A grouped training module for training the model using at least one set of subclass positive samples and subclass negative samples, where the subclass positive samples are used to train the corresponding submodels and scoring modules configured in the attack module of the model, and the subclass negative samples are used to train the corresponding submodels configured in the defense module of the model;
[0040] A hyperparameter tuning module, which is used to find the best parameter combination through a hyperparameter tuning algorithm, train and optimize a model through a cross-entropy loss function, and use the trained model after iteration as an auxiliary training model;
[0041] An application module, which is used to obtain vulnerability information of both systems, and use the trained auxiliary training model to give attack behaviors, defense behaviors, and vulnerability level scores for the vulnerability information.
[0042] Thirdly, an embodiment of the present invention provides a network security competition drill system, including an auxiliary training model constructed by the network security competition auxiliary training model construction method described in the first aspect.
[0043] Fourthly, an embodiment of the present invention provides an electronic device, including a processor, a communication interface, a memory, and a bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the bus, and the processor can call logical instructions in the memory to execute the steps of the method provided in the first aspect.
[0044] Fifthly, an embodiment of the present invention provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the network security competition auxiliary training model construction method described in the first aspect.
[0045] Compared with the prior art, the beneficial effects of the network security competition auxiliary training model construction device, drill system, electronic device, and storage medium of the present invention are the same as those of the network security competition auxiliary training model construction method described in the first aspect, so they will not be elaborated here. Description of the Drawings
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0047] Figure 1 It is the architecture diagram of the auxiliary training model in the embodiment of the present invention;
[0048] Figure 2 It is the flowchart of the network security competition auxiliary training model construction method in the embodiment of the present invention;
[0049] Figure 3 It is the structural block diagram of the network security competition auxiliary training model construction device in the embodiment of the present invention;
[0050] Figure 4This is the structural block diagram of the electronic device in the embodiment of the present invention. Detailed implementation manners
[0051] To better understand the purpose, technical solution and advantages of the present application, the present application will be described and illustrated below with reference to the accompanying drawings and embodiments.
[0052] Unless otherwise defined, the technical terms or scientific terms involved in the present application shall have the general meaning understood by those with ordinary skills in the technical field to which the present application belongs. In the present application, words such as "a", "one", "a kind of", "the", "these" and the like do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "comprising", "having" and any variants thereof involved in the present application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The terms "connected", "coupled" and the like involved in the present application are not limited to physical or mechanical connections, but may include electrical connections, whether directly or indirectly connected. The "plurality" involved in the present application means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects associated before and after are in an "or" relationship. The terms "first", "second", "third" and the like involved in the present application are only used to distinguish similar objects and do not represent a specific sorting of the objects.
[0053] In the embodiment of the present invention, a method for constructing an auxiliary training model for a network security competition is provided. Figure 2 This is the flowchart of the method for constructing an auxiliary training model for a network security competition of the present invention. As Figure 1 and Figure 2 shown, the process includes the following steps:
[0054] S100. Obtain raw data from a network security database and a historical attack and defense database, and preprocess the raw data to obtain a labeled sample training set, where the samples include positive samples and negative samples;
[0055] The raw data is the data required for training the model. It should be noted that the data types will be elaborated in detail in the training processes of the respective sub-models of the attack module and the defense module below.
[0056] Specifically, in this embodiment, raw data is obtained from a network security database and a historical attack and defense database, and the raw data is preprocessed to obtain a labeled sample training set, including:
[0057] Obtain raw data, which includes a vulnerability set, attack vectors, internal logs, service configurations, traffic monitoring, vulnerability data, historical cases, and defense strategies;
[0058] Clean the raw data to obtain processed samples; among them, data cleaning removes invalid and incorrect data.
[0059] Classify and label the processed samples to obtain positive samples and negative samples.
[0060] Classify and label the samples so that the machine learning model can learn. It should be noted that in this embodiment, the positive samples are real attack behavior data from the raw data, and the negative samples are normal network activity data. The specific training process will be described later.
[0061] S200. Perform secondary classification on the positive samples and negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0062] Specifically, performing secondary classification on the positive samples and negative samples to obtain at least one set of subclass positive samples and subclass negative samples includes:
[0063] Obtain sub-model information configured by the model attack module, model defense module, and scoring module, as well as the required training sample data;
[0064] Perform secondary classification on the positive samples and negative samples according to the sub-model information and the required sample data to obtain at least one set of subclass positive samples and subclass negative samples;
[0065] Use the subclass positive samples and subclass negative samples to train the sub-models configured by the model attack module, scoring module, and model defense module.
[0066] S300. Use at least one set of subclass positive samples and subclass negative samples to train the model. Among them, the subclass positive samples are used to train the corresponding sub-models configured by the attack module of the model and the scoring module, and the subclass negative samples are used to train the corresponding sub-models configured by the defense module of the model;
[0067] It should be noted that in this embodiment, since multiple sub-models are configured for the attack module and the defense module, a modular architecture design is adopted. Each sub-model is an independent module, and the advantages of multiple sub-models can be combined through advanced fusion technologies such as stacking generalization and weighted voting, making the overall performance of the trained model stronger.
[0068] In this embodiment, the attack module configures multiple models. The sub-models configured by the attack module include generative adversarial networks, classification models, reinforcement learning models, and sequence models.
[0069] Exemplarily, generative adversarial networks (GANs) include a generator and a discriminator. Among them, the generator is used to create data simulating real attacks, and the discriminator is used to distinguish between real and fake data. Adversarial training is carried out, that is, the generator and the discriminator are alternately trained. The generator tries to deceive the discriminator so that it cannot correctly distinguish the generated data from the real data; while the discriminator tries to improve its discrimination ability. When the data generated by the generator can be misrecognized as real data with a high enough probability, the training process can stop. It should be noted that for the training of GANs, real attack samples (subclass positive samples) are used as the learning materials for the discriminator, and initial noise or randomly generated data is used as the input for the generator.
[0070] The training process of the classification model includes: collecting and annotating a large amount of network traffic data, which contains normal traffic (negative samples) and known attack patterns (positive samples). Each sample includes a feature vector and a corresponding label. Select classification algorithms such as SVM, random forest, or GBDT, and set initial parameters according to prior knowledge or hyperparameter tuning. Divide the preprocessed data set into a training set and a validation set. Use the training set to train the model and adjust the model parameters by minimizing the loss function. Evaluation and optimization: Evaluate the model performance on the validation set, and adopt the cross-validation method to avoid overfitting. Adjust the hyperparameters or the model structure according to the evaluation results until satisfactory performance indicators are achieved.
[0071] The training samples of the classification model include positive samples and negative samples. Among them, the positive samples are real attack behavior data from historical records, and the negative samples are normal network activity data.
[0072] The training process of the sequence model includes: obtaining training samples, which are time series data, such as continuous network requests or system log entries, marked as normal or attack behaviors. Extract features from the time series data to form a time step sequence suitable for the input format of the RNN. Use the backpropagation through time (BPTT) algorithm to update the weights, predict future attack behaviors, and adjust the model parameters through multiple iterations to ensure prediction accuracy.
[0073] The training process of the reinforcement learning model includes: obtaining training samples, which are interaction experiences in a simulated environment, that is, a series of state, action, and reward triples. Specifically, set up a simulated environment, define the state space, action space, and reward mechanism. The agent executes actions in the environment, obtains rewards or punishments according to the environmental feedback, and then updates the policy. As the number of training times increases, the agent gradually learns more effective attack strategies.
[0074] In this embodiment, the sub-models configured in the defense module include an intrusion detection and prevention system model, a deep learning model, a rule engine combined with a machine learning model, and a graph neural network.
[0075] Among them, the training process of the intrusion detection and prevention system model (IDS model) includes: obtaining training samples, which are labeled network traffic data, including normal traffic and various types of attack traffic. Specifically, features are extracted from the original data, and the extracted features can effectively distinguish normal behaviors and attack behaviors. For supervised IDS, data with labels is used for training; for unsupervised IDS, it may only rely on unlabeled data. Determine the alarm threshold to trigger an alarm when an anomaly is detected.
[0076] The training process of the deep learning model includes: obtaining training samples, which are network traffic data. Usually, a large number of samples are required to capture different types of threats. Specifically, network packets are converted into a form suitable for input to the deep learning model, such as an image representation or a feature matrix, and the weights of the neural network are adjusted using the backpropagation algorithm to make the output as close as possible to the target value.
[0077] The training process of the rule engine combined with the machine learning model includes: obtaining training samples, which include log entries that match rules and abnormal events that do not match rules but are confirmed manually. Specifically, a rule base based on domain expert knowledge is established. A machine learning model is used to identify new threats not covered by the rules. The results of the rule engine and the machine learning model are combined for a final judgment.
[0078] The training process of the graph neural network includes: obtaining training samples, which are data describing the network structure and its dynamic changes, as well as associated security event records. Create a graph representing the network topology, where nodes represent hosts or services and edges represent connection relationships. Pass information on the network graph to share features between adjacent nodes. Update the embedding representation of the current node based on the information of neighboring nodes to better understand the global context.
[0079] S400. Find the best parameter combination through a hyperparameter tuning algorithm, train and optimize the model through a cross-entropy loss function, and use the model after training iteration as an auxiliary training model;
[0080] In this embodiment, AutoML tools such as Hyperopt and Optuna can be introduced to find the hyperparameter combination faster and are easily integrated into the existing workflow.
[0081] ;
[0082] where N is the number of samples, is the true label (0 or 1) of the i-th sample, It is the probability that the i-th sample predicted by the model is a positive class.
[0083] Optionally, the model is optimized using grid search. A total of four parameters are set: max_depth (the maximum depth of the tree), min_child_weight (the minimum weight of the leaf node), n_estimators (the number of trees), and learning_rate (the learning rate). The parameters are set as follows: max_depth: [3, 5, 7], min_child_weight: [1, 3, 6], n_estimators: [100, 200, 300], learning_rate: [0.01, 0.05, 0.1].
[0084] S500. Obtain the system vulnerability information of both sides, and use the trained auxiliary training model to give attack behaviors, defense behaviors, and vulnerability level scores for the system vulnerability information.
[0085] It should be noted that in this embodiment, through vulnerability scanning tools, such as Nmap for network scanning, OpenVAS and Nessus for vulnerability scanning, open port and service version information is obtained, and search engines such as Shodan and Censys are used to find devices and services exposed on the external network. It should be further noted that the vulnerabilities can also be based on the vulnerability topics given in the competition, as well as the vulnerability information in the network security database and the historical attack and defense database.
[0086] Specifically, obtaining the system vulnerability information of both sides, and using the trained auxiliary training model to give vulnerability level scores for the system vulnerability information, including:
[0087] Using a vulnerability scanning tool to obtain the system vulnerabilities of the opposing party , analyzing the vulnerabilities to obtain each vulnerability 's influencing factors, and setting a basic weight for each influencing factor of each vulnerability ;
[0088] Specifically, according to the network security competition rules, the influencing factors of the vulnerabilities are preset. In this embodiment, the vulnerability influencing factors include required permissions PR, attack vector AV, attack complexity AC, scope of impact S, and attack feasibility A. A basic weight is assigned to each influencing factor. Among them, the weight of required permissions PR is , the weight of attack vector AV is , the weight of attack complexity AC is , the weight of scope of impact S is , the weight of attack feasibility A is , it should be noted that the sum of the weights is 1, that is .
[0089] Obtain the importance index score of the vulnerability according to the calculation formula of each basic weight;
[0090] For each vulnerability Perform a weighted score on the importance index score, and the formula is as follows:
[0091] ;
[0092] Among them, is the score of the required permissions for the vulnerability , is the score of the attack vector of the vulnerability ; is the score of the attack complexity of the vulnerability ; is the score of the affected range of the vulnerability ; is the score of the attack feasibility of the vulnerability ;
[0093] Based on the importance index score Sort the importance levels of the vulnerabilities.
[0094] In this embodiment, according to the importance index score of each vulnerability Sort the importance of the vulnerabilities from high to low for reference when contestants conduct simulation training.
[0095] Furthermore, obtain the system vulnerability information of both parties, and use the trained auxiliary training model to give attack behaviors for the system vulnerability information, including:
[0096] Obtain the vulnerability information and the level score of each vulnerability, and conduct in-depth analysis on each vulnerability to extract key features;
[0097] Conduct in-depth analysis on each vulnerability to extract its key features, such as the affected service or application version, exploitation method, required permissions, etc.
[0098] Use the trained generative adversarial network (GANs) to generate attack vectors according to the input key features of the vulnerability;
[0099] Specifically, use the trained classification model or generative adversarial network (GANs) to generate possible attack vectors according to the input vulnerability features. For example, if the vulnerability involves SQL injection, generate the corresponding SQL injection statement; if it is a buffer overflow, construct a malicious data packet. For certain specific types of vulnerabilities, a set of rules can be predefined to guide how to construct effective attack payloads, and the rules can be established based on historical data and expert knowledge.
[0100] Furthermore, for the formulation of attack strategies, graph neural networks (GNNs) are used to simulate and predict the most likely successful attack routes, which can consider factors such as the configuration of the target system and the network topology to determine the most suitable attack path. These decision-making processes can be optimized through reinforcement learning to find the best strategy through continuous attempts.
[0101] Generate attack behaviors by using the generated attack vectors through penetration testing tools.
[0102] Specifically, integrate the generated attack vectors into existing penetration testing tools such as Metasploit, Nessus, etc. to achieve an automated attack process. Adjust the attack parameters according to real-time feedback to ensure the maximization of the attack effect while reducing the risk of being detected. For example, if it is found that a certain attack method triggers the intrusion detection system (IDS), immediately switch to another method with low noise.
[0103] Obtain the vulnerability information of both systems, and use the trained auxiliary training model to give defensive behaviors based on the system vulnerability information, including:
[0104] Obtain the vulnerability information and the level score of each vulnerability;
[0105] When conducting defensive training, the vulnerability information and the level score of the vulnerability can also be obtained.
[0106] Update the signature library and rule set of the intrusion detection and prevention system model based on the latest vulnerability information, and conduct defense according to the vulnerability information.
[0107] For example, based on the latest vulnerability information, the IDS model will update its internal attack feature signature library and rule set. For example, if a new SQL injection vulnerability is discovered, the IDS will add the attack pattern corresponding to this vulnerability to its detection rules so that it can identify and warn against such attacks. The IDS continuously monitors network traffic and uses machine learning algorithms to analyze whether the data packets conform to known attack patterns or abnormal behaviors. Once it detects activities that may exploit specific vulnerabilities, it will trigger an alarm and record detailed event logs.
[0108] Deep learning models can automatically extract features from a large amount of historical data and learn the differences between normal traffic and malicious traffic. When new vulnerabilities emerge, through transfer learning or fine-tuning pre-trained models, they can quickly adapt to new threat situations. By using deep learning models to predict possible future attacks, defensive measures can be deployed in advance. For example, the model can predict which types of attacks are more likely to occur based on changes in the current network environment and strengthen protection accordingly. The rule engine checks traffic according to preset security policies, while the machine learning part is responsible for identifying new types of threats not covered by existing rules. The combination of the two can provide more comprehensive protection. As more information about vulnerabilities is obtained, the rule engine can dynamically adjust its rule set, and at the same time, the machine learning model can be retrained to improve accuracy. Graph neural networks are good at processing complex relational data, such as network topology diagrams. It can help understand the nodes (hosts, services, etc.) and their connection methods in the entire network architecture, so as to better evaluate the potential impact of a certain vulnerability within the entire system. Based on the understanding of the network structure, GNN can simulate the best paths that an attacker might take and suggest the best locations to deploy additional security control points, such as firewall rules, intranet isolation, etc., to prevent attackers from using vulnerabilities to penetrate the network deeply.
[0109] An embodiment of the present invention also provides a device for constructing an auxiliary training model for a network security competition. This device is used to implement the above method embodiments, and those that have been described will not be repeated here. The following terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware or a combination of software and hardware is also possible and contemplated.
[0110] As Figure 3 shown, Figure 3 is a structural block diagram of a device for constructing an auxiliary training model for a network security competition. This device includes:
[0111] A preprocessing module 101, which is used to obtain raw data from a network security database and a historical attack and defense database, and preprocess the raw data to obtain a labeled sample training set. The samples include positive samples and negative samples;
[0112] A secondary classification module 102, which is used to perform secondary classification on positive samples and negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0113] A grouped training module 103, which is used to train the model using at least one set of subclass positive samples and subclass negative samples. Among them, the subclass positive samples are used to train the corresponding sub-models and scoring modules configured in the attack module of the model, and the subclass negative samples are used to train the corresponding sub-models configured in the defense module of the model;
[0114] The hyperparameter tuning module 104 is used to find the best parameter combination through a hyperparameter tuning algorithm, train and optimize the model through a cross-entropy loss function, and use the iteratively trained model as an auxiliary training model.
[0115] The drill module 105 is used to obtain the vulnerability information of both systems, and use the trained auxiliary training model to give attack behaviors, defense behaviors, and vulnerability level scores for the system vulnerability information.
[0116] The embodiment of the present invention also provides a network security competition drill system, including an auxiliary training model constructed by the network security competition auxiliary training model construction method in the first aspect.
[0117] In this embodiment, the auxiliary training model is respectively configured on the attacking end and the defending end. The attacking end uses the auxiliary training model to simulate threats, and the defending end uses the auxiliary training model to adjust the defense strategy according to the simulated threats.
[0118] Specifically, the trained auxiliary training model is deployed to the competition environment. It should be noted that it is ensured that the auxiliary training model can receive and analyze network data in real time, and necessary hardware and software resources are configured to ensure the operation efficiency and stability of the auxiliary training model.
[0119] In the network security competition drill system of this embodiment, the auxiliary training model is respectively configured on the attacking end and the defending end. The attacking end using the auxiliary training model to simulate threats includes:
[0120] Identify the target system and obtain the basic data of the target system. The basic data includes network structure, system configuration, and security vulnerabilities; the auxiliary training model will use technologies such as big data analysis and machine learning to intelligently identify the target system, analyze its network structure, system configuration, security vulnerability and other information, and provide basic data for subsequent attacks.
[0121] According to the basic data of the target system, the auxiliary training model automatically adjusts the attack parameters and simulates an advanced attack sequence. Exemplarily, according to the defense ability and reaction speed of the target system, the auxiliary training model will dynamically adjust the attack intensity to avoid prematurely exposing itself or triggering the alarm of the defense system. For example, use low-intensity scans during the detection phase to avoid triggering the alarm of the IDS (intrusion detection system), and gradually increase the attack intensity during the attack phase to quickly break through the defense.
[0122] The auxiliary training model will also intelligently select the optimal attack path according to the network topology structure, firewall rules and other information of the target system to bypass the monitoring and interception of the defense system;
[0123] It should be noted that initial intelligence collection will be carried out before simulating the advanced attack sequence: the auxiliary training model will conduct intelligence collection, including scanning the IP addresses, domain names, open ports, etc. of the target system to prepare for subsequent attacks. After the preparation is completed, it can simulate complex attack sequences including social engineering attacks and zero-day vulnerability exploitation to challenge the defense system of the participating teams.
[0124] Furthermore, the threats simulated by the attacking side using the auxiliary training model also include:
[0125] According to the obtained security vulnerability information, obtain low privileges on the target system through vulnerability exploitation;
[0126] Using the security vulnerability information obtained during the scanning process, the auxiliary training model will attempt to exploit vulnerabilities, such as obtaining database privileges through SQL injection and uploading malicious files through file inclusion vulnerabilities.
[0127] Perform privilege escalation operations based on the low privileges of the target system to obtain high privileges on the target system;
[0128] When the low privileges of the target system are successfully obtained, the auxiliary training model will attempt to perform privilege escalation operations to obtain higher privileges on the target system.
[0129] After obtaining high privileges on the target system, control the internal network of the target system through internal network penetration.
[0130] After obtaining system privileges, the auxiliary training model will attempt internal network penetration and further control the internal network of the target system through means such as lateral movement and password cracking. Furthermore, in order to maintain continuous control of the target system, the auxiliary training model will attempt to deploy malicious software such as backdoor programs and Trojans to launch attacks at any time when needed.
[0131] The defensive side uses the auxiliary training model to adjust the defense strategy according to the simulated threats, including:
[0132] Obtain the current attack and defense dynamics, which include attack type, attack intensity, attack frequency, potential threats, the behavior patterns and characteristics of the attacking side;
[0133] Provide the current defense strategy through the auxiliary training model according to the current attack and defense dynamics.
[0134] Specifically, use the auxiliary training model to monitor the attack and defense dynamics in the competition, analyze the actions of both sides, and provide immediate strategy suggestions for the defensive side, such as adjusting firewall rules and deploying honeypots, etc., to minimize losses and counterattack. In addition, the auxiliary training model set on the defensive side monitors the security status of its own system in real time, discovers and responds to potential security threats in a timely manner; dynamically adjusts the defense strategy according to the behavior patterns and characteristics of the attacker, such as strengthening firewall rules and updating security patches.
[0135] It also includes effect evaluation: The auxiliary training model evaluates the attacks of the attacking side and the defenses of the defending side to obtain scores and losses.
[0136] Furthermore, in the competition, the auxiliary training model can analyze the strengths and weaknesses of each team, customize attack scenarios of different difficulties and types, prompt the participating teams to specifically improve their own weaknesses, and at the same time conduct actual combat simulation training by simulating the attack patterns of their specific opponents.
[0137] Figure 4 It is the structural block diagram of the electronic device provided by the embodiment of the present invention. As Figure 4 shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640. Among them, the processor 610, the communications interface 620, and the memory 630 complete communication with each other through the communication bus 640. The processor 610 can call the logical instructions in the memory 630 to execute the following methods:
[0138] Obtain raw data from the network security database and the historical attack and defense database, and preprocess the raw data to obtain a labeled sample training set. The samples include positive samples and negative samples;
[0139] Perform secondary classification on the positive samples and negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0140] Use at least one set of subclass positive samples and subclass negative samples to train the model. Among them, the subclass positive samples are used to train the corresponding submodels and scoring modules configured in the attack module of the model, and the subclass negative samples are used to train the corresponding submodels configured in the defense module of the model;
[0141] Find the best parameter combination through the hyperparameter tuning algorithm, train and optimize the model through the cross-entropy loss function, and use the iteratively trained model as the auxiliary training model;
[0142] Obtain the vulnerability information of both systems, and use the trained auxiliary training model to give attack behaviors, defense behaviors, and vulnerability level scores for the system vulnerability information.
[0143] In addition, when the logical instructions in the above-mentioned memory 630 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0144] The embodiments of the present invention further provide a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the methods provided in the above-mentioned various embodiments, for example, including:
[0145] Obtain raw data from the network security database and the historical attack and defense database, and preprocess the raw data to obtain a labeled sample training set, where the samples include positive samples and negative samples;
[0146] Perform secondary classification on the positive samples and negative samples to obtain at least one set of subclass positive samples and subclass negative samples;
[0147] Use at least one set of subclass positive samples and subclass negative samples to train the model. Among them, the subclass positive samples are used to train the corresponding sub-models and scoring modules configured for the attack module of the model, and the subclass negative samples are used to train the corresponding sub-models configured for the defense module of the model;
[0148] Find the best parameter combination through a hyperparameter tuning algorithm, train and optimize the model through a cross-entropy loss function, and use the iteratively trained model as an auxiliary training model;
[0149] Obtain the system vulnerability information of both parties, and use the trained auxiliary training model to give attack behaviors, defense behaviors, and vulnerability level scores for the system vulnerability information.
[0150] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments.
[0151] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for constructing a network security competition-assisted training model, characterized in that: The construction method comprises: Obtaining raw data from a network security database and a historical attack and defense database, and preprocessing the raw data to obtain a labeled sample training set, wherein the samples include positive samples and negative samples; Performing secondary classification on the positive samples and the negative samples to obtain at least one group of subclass positive samples and subclass negative samples; The positive samples and the negative samples are classified twice to obtain at least one group of subclass positive samples and subclass negative samples, including: Obtain the sub-model information configured in the model attack module, model defense module, and scoring module, as well as the required training sample data; Secondarily classify the positive samples and negative samples according to the sub-model information and the required training sample data to obtain at least one group of sub-class positive samples and sub-class negative samples; Using subclass positive samples and subclass negative samples to train the submodels configured by the model attack module, the scoring module, and the model defense module; The model is trained using at least one group of subclass positive samples and subclass negative samples, wherein the subclass positive samples are used to train the corresponding submodels and scoring modules configured in the attack module of the model, and the subclass negative samples are used to train the corresponding submodels configured in the defense module of the model; Find the best parameter combination through the hyperparameter tuning algorithm, train and optimize the model through the cross entropy loss function, and use the model after training iteration as the auxiliary training model; The vulnerability information of both systems is obtained, and the trained auxiliary training model is used to give attack behavior, defense behavior and vulnerability level scores according to the system vulnerability information.
2. The method for constructing a network security competition auxiliary training model according to claim 1, characterized in that: The original data is obtained from the network security database and the historical attack and defense database, and the original data is preprocessed to obtain a labeled sample training set, including: Obtaining raw data, including vulnerability sets, attack vectors, internal logs, service configurations, traffic monitoring, vulnerability data, historical cases, and defense strategies; Performing data cleaning on the raw data to obtain processed samples; The processed samples are classified and labeled to obtain positive samples and negative samples.
3. The method for constructing a network security competition auxiliary training model according to claim 1, characterized in that: The sub-models configured in the attack module include generative adversarial networks, classification models, reinforcement learning models, and sequence models; the sub-models configured in the defense module include intrusion detection and prevention system models, deep learning models, rule engines combined with machine learning models, and graph neural networks.
4. The method for constructing a network security competition auxiliary training model according to claim 3, characterized in that: Obtain the vulnerability information of both systems, and use the trained auxiliary training model to give attack behaviors based on the system vulnerability information, including: Obtain vulnerability information and the level score of each vulnerability, and conduct in-depth analysis of each vulnerability to extract key features; Use the trained generative adversarial network to generate attack vectors based on the key features of the input vulnerability; The generated attack vector is used to generate attack behavior through a penetration testing tool.
5. The method for constructing a network security competition auxiliary training model according to claim 3, characterized in that: Obtain the vulnerability information of both systems, and use the trained auxiliary training model to provide defensive actions based on the system vulnerability information, including: Obtain vulnerability information and a rating score for each vulnerability; Update the signature library and rule set of the intrusion detection and prevention system model based on the latest vulnerability information, and perform defense based on the vulnerability information.
6. The method for constructing a network security competition auxiliary training model according to claim 1, characterized in that: Obtain vulnerability information of both systems, and use the trained auxiliary training model to give vulnerability level scores for the system vulnerability information, including: Use vulnerability scanning tools to obtain system vulnerabilities of the adversary, analyze the vulnerabilities, obtain the influencing factors of each vulnerability, and set basic weights for each of the influencing factors of each vulnerability; The importance index score of the vulnerability is obtained according to the calculation formula of each basic weight; The vulnerabilities are ranked according to their importance levels based on the importance index scores.
7. A network security competition auxiliary training model construction device, characterized in that: include: A preprocessing module, used to obtain raw data from a network security database and a historical attack and defense database, and preprocess the raw data to obtain a labeled sample training set, wherein the samples include positive samples and negative samples; A secondary classification module, used for secondary classification of the positive samples and the negative samples to obtain at least one group of subclass positive samples and subclass negative samples; The positive samples and the negative samples are classified twice to obtain at least one group of subclass positive samples and subclass negative samples, including: Obtain the sub-model information configured in the model attack module, model defense module, and scoring module, as well as the required training sample data; Secondarily classify the positive samples and negative samples according to the sub-model information and the required training sample data to obtain at least one group of sub-class positive samples and sub-class negative samples; Using subclass positive samples and subclass negative samples to train the submodels configured by the model attack module, the scoring module, and the model defense module; A group training module, used to train the model using at least one group of subclass positive samples and subclass negative samples, wherein the subclass positive samples are used to train the corresponding submodels and scoring modules configured in the attack module of the model, and the subclass negative samples are used to train the corresponding submodels configured in the defense module of the model; The hyperparameter tuning module is used to find the best parameter combination through the hyperparameter tuning algorithm, train the optimization model through the cross entropy loss function, and use the model after training iteration as the auxiliary training model; The application module is used to obtain the system vulnerability information of both parties, and use the trained auxiliary training model to give attack behavior, defense behavior and vulnerability level score for the system vulnerability information.
8. A network security competition training system, characterized in that: An auxiliary training model constructed by the method for constructing an auxiliary training model for a network security competition as described in any one of claims 1 to 6.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the method for constructing a network security competition assisted training model as described in any one of claims 1 to 6.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for constructing a network security competition-assisted training model as described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Multi-dimensional software security risk assessment method based on CVSS
CN114065223A
Network security training method based on simulated network
CN115549965A
Network security evaluation system and method based on dynamic attack and defense game model
CN119544307A