Shooting range privatization deployment mode application system

Through the privatized deployment mode application system of the shooting range, the shortcomings of traditional public shooting ranges in data security and customization have been solved, efficient network security training and testing have been achieved, and the efficiency of security strategies and the security of enterprise data assets have been significantly improved.

CN119987790APending Publication Date: 2025-05-13INTEGRITY TECH GRP INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411818255.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Traditional public shooting ranges have defects in data security and customization, and cannot effectively protect enterprise sensitive data and cannot accurately simulate the enterprise's unique network environment, making it difficult to migrate and apply training and testing results.

Method used

It provides a private deployment mode application system for shooting ranges, including a central server and multiple cloud dock nodes. The central server is used to manage the shooting range environment and user permissions. The cloud dock node is used to perform network security tasks, realize customized shooting range environment and real-time monitoring and feedback.

Benefits of technology

Effectively resolve data leakage risks, improve the pertinence and accuracy of security training and testing, accelerate the implementation of security strategies in actual business, and ensure the security of enterprise data assets and the stability of business operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987790A_ABST
    Figure CN119987790A_ABST
Patent Text Reader

Abstract

The invention discloses a target range privatization deployment mode application system. The system provided by the invention can effectively solve the risk of data leakage, build a solid foundation for enterprise network security training and testing, greatly improve the pertinence and accuracy of security training and testing, and accelerate the efficient landing of security strategies in actual services. User operation behaviors can be accurately captured, a deep analysis report and strategy guidance can be generated in real time, the user is assisted to rapidly insight into the training effect, accurately locate weak links and agilely adjust the training strategy, and the safety skill improvement efficiency is remarkably improved; the method can protect enterprise data assets, effectively cope with potential data disasters, ensure service operation stability and continuity, comprehensively meet multiple requirements of enterprise network security construction, and assist enterprises to steadily move forward in a complex network security situation and occupy a precedent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an application system for a privatized deployment mode of a shooting range. Background Art

[0002] In today's digital age, cyber attack methods continue to evolve and become more complex, resulting in an urgent need for enterprises to improve their cybersecurity protection capabilities. Traditional cybersecurity training and testing mostly rely on public shooting ranges, whose architecture and operation mode have many defects. In terms of data security, the public shooting range environment causes enterprises' sensitive data to face serious leakage risks. Once attackers break through the protection boundary, the core business data of the enterprise, user privacy information, etc. are easily stolen or tampered with, which in turn causes significant economic losses and reputation crises.

[0003] From a customized perspective, the unified scenario settings of public ranges cannot meet the unique business architecture and security demands of each enterprise. It is difficult for enterprises to accurately simulate the attack and defense scenarios in their own real network environment, resulting in poor migration and application of training and testing results to actual business scenarios. Furthermore, given the ever-changing network security situation, the public ranges lack flexibility in resource allocation and are unable to respond to the urgent or special security testing needs of enterprises in a timely manner, which severely limits the autonomy of enterprises in the process of building security capabilities.

[0004] With the acceleration of the localization of information technology, the ICT industry is booming. In the field of network security, building a technical architecture that is compatible with domestic ICT CPUs (such as Hygon, Kunpeng, Zhaoxin, etc.) and operating systems (such as Kylin, Tongxin, etc.) has become a key path to ensure national information security and achieve independent and controllable strategic goals. In this context, the privatized deployment range model has emerged, which has great potential in ensuring data security, providing customized services, and integrating ICT technologies, becoming one of the core trends of network security technology innovation. Summary of the invention

[0005] The present application provides an application system for a privatized deployment model of a target range, which can effectively resolve the risk of data leakage, lay a solid foundation for enterprise network security training and testing, greatly improve the pertinence and accuracy of security training and testing, and accelerate the efficient implementation of security strategies in actual business; it can accurately capture user operation behaviors, generate in-depth analysis reports and policy guidance in real time, and help users quickly understand the effectiveness of training, accurately locate weak links, and agilely adjust training strategies, significantly improving the efficiency of improving security skills; it can protect enterprise data assets, effectively respond to potential data disasters, ensure the stability and continuity of business operations, and fully meet the diverse needs of enterprise network security construction, helping enterprises to move forward steadily and seize the initiative in complex network security situations.

[0006] In a first aspect, the present application provides a shooting range privatization deployment mode application system, the system comprising a central server and a plurality of cloud base nodes;

[0007] The central server is used to manage the range environment, user permissions, and cloud management platform access in response to management instructions, and to schedule and configure the computing resources, network resources, and storage resources of the cloud base node according to the network security tasks corresponding to the management instructions; and to display the real-time dynamic information of the cloud base node executing the network security tasks;

[0008] The cloud base node is used to respond to the scheduling and configuration instructions of the central server for the network security task, and utilize the computing resources, network resources, and storage resources in the cloud base node to perform network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security task.

[0009] Optionally, the central server is specifically used to set, dynamically adjust and allocate the user's access rights and operation rights according to the user's role positioning in the organizational structure, business responsibilities and security level requirements.

[0010] Optionally, the central server includes a service delivery module;

[0011] The service delivery module includes a visual orchestration module, an operation management module and a scenario center module;

[0012] The visual orchestration module is used for network element management, topology management, scenario encapsulation and one-click publishing. Through visual orchestration, users drag and drop components of network element devices to build a custom topology and save it as a scenario. Through the scenario center, a one-click scenario self-test is issued to obtain an access address test. After the self-test is completed, the scenario can be bound to a scenario mode for competition, training, or teaching.

[0013] The operation management module is used to perform competition management, training management, access control and teaching management on the network security task;

[0014] The scenario center module is used to perform scenario self-testing and scenario management on the attack and defense drills of the network security tasks; and customize the shooting range environment according to user needs, wherein the shooting range environment includes network structure, attack scenarios and defense strategies.

[0015] Optionally, the visual orchestration module is specifically used for users to customize the target range network architecture, configure attack scenario details, and plan the defense strategy hierarchy based on business logic, security policy orientation and personalized needs by relying on the convenient drag and drop function of the visual interface, so as to achieve a high degree of fit between the target range environment and the actual business scenarios of the enterprise and enhance the practical effectiveness of security training and testing.

[0016] Optionally, the central server includes a platform capability module;

[0017] The platform capability module includes computing services, storage services and network services;

[0018] The computing service is used to provide virtualized CPU memory computing resources for the target range of the network security task;

[0019] The storage service is used to provide storage resources and data backup for the range virtualization resources of the network security task;

[0020] The network service is used to provide network interoperability for the target range virtualization host of the network security task; wherein the network interoperability includes at least one of the following: port traffic mirroring analysis and real-time service status monitoring, VPC network isolation and security group support between target ranges, and support for VPC isolation, security group, operation audit, and two-factor authentication functions.

[0021] Optionally, the network service is specifically used to monitor and record in real time every operation detail, every decision trajectory and every interaction behavior of the user in the shooting range environment, and through real-time data processing and intelligent feedback mechanism, timely present operation effectiveness evaluation, potential risk warning and optimization strategy suggestions to the user, helping the user to optimize the training path in real time.

[0022] Optionally, each cloud base node includes a virtualization layer;

[0023] The virtualization layer includes a computing resource pool, a storage resource pool and a network resource pool;

[0024] The computing resource pool is used to aggregate and manage CPU and memory computing resources;

[0025] The storage resource pool is used to manage storage resources in a centralized manner;

[0026] The network resource pool is used to provide management capabilities for network resources of public networks, flat networks, and vpc networks.

[0027] Optionally, each cloud base node includes an infrastructure module;

[0028] The infrastructure module includes a SAN storage module, a physical switch and a physical server;

[0029] The SAN storage module is used to generate a storage solution based on the network, connected via a fiber channel, suitable for a high-performance computing environment, and to provide a data protection strategy;

[0030] The physical switch is used to provide a network lease;

[0031] The physical server is used to provide computing resources and storage resources, flexible switching between EC and replica dual mechanisms, and data encryption and backup functions to ensure the security and recoverability of training data.

[0032] Optionally, the physical server is specifically used to use an encryption algorithm to perform real-time encryption processing on the training data to ensure the confidentiality, integrity and non-tamperability of the data during storage and transmission; at the same time, relying on intelligent backup strategies and reliable storage architecture, it supports flexible switching of multi-copy storage modes and EC erasure code technology, and ensures that the data can be accurately restored to any specified historical version in the event of accidental damage or loss of data, thereby ensuring business continuity and data asset integrity.

[0033] Optionally, the system further includes an operation and maintenance system;

[0034] The operation and maintenance system includes a platform monitoring module, a permission control module, a data warehouse, an alarm center, an operation record module and an account management module;

[0035] The platform monitoring module is used to monitor virtual resources and physical machine resources;

[0036] The permission control module is used to control the user's access to the platform;

[0037] The data warehouse is used to store the mirror data and manage the majority of the mirror data;

[0038] The alarm center is used to push alarm information to users;

[0039] The operation recording module is used to record the user operation history;

[0040] The account management is used to add, delete, adjust and query the accounts of administrators and student users.

[0041] It can be seen from the above technical scheme that the present application provides an application system for a shooting range privatization deployment mode, the system comprising a central server and multiple cloud base nodes; the central server is used to respond to management instructions to manage the shooting range environment, user permissions, and cloud management platform access, and, according to the network security tasks corresponding to the management instructions, the computing resources, network resources, and storage resources of the cloud base nodes are scheduled and configured; and real-time dynamic information of the cloud base nodes executing the network security tasks is displayed; the cloud base nodes are used to respond to the scheduling and configuration instructions of the central server for the network security tasks, and utilize the computing resources, network resources, and storage resources in the cloud base nodes to execute the network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security tasks. It can be seen that the application system of the privatized deployment model of the shooting range in this application has multiple significant advantages; in terms of security performance, it can effectively resolve the risk of data leakage and lay a solid foundation for enterprise network security training and testing; in terms of customization, users can schedule and configure the computing resources, network resources, and storage resources of the cloud base node, that is, customize the shooting range environment that fits the business scenario on demand, greatly improve the pertinence and accuracy of security training and testing, and accelerate the efficient implementation of security strategies in actual business. As one of the core advantages, the real-time monitoring and feedback mechanism (i.e., displaying the real-time dynamic information of the cloud base node performing the network security task) can accurately capture user operation behavior, generate in-depth analysis reports and policy guidance in real time, and help users quickly gain insight into training results, accurately locate weak links, and agilely adjust training strategies, significantly improving the efficiency of improving security skills. By utilizing the computing resources, network resources, and storage resources in the cloud base nodes to perform network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security tasks, it can protect enterprise data assets, effectively respond to potential data disasters, ensure business operation stability and continuity, and fully meet the diverse needs of enterprise network security construction, helping enterprises to move forward steadily and gain the upper hand in complex network security situations.

[0042] The further effects of the above-mentioned non-conventional preferred manner will be described below in conjunction with specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present application or the existing technical solutions, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0044] Figure 1A schematic diagram of the system architecture of a shooting range privatization deployment mode application system provided in one embodiment of the present application. DETAILED DESCRIPTION

[0045] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0046] Various non-limiting implementations of the present application are described in detail below in conjunction with the accompanying drawings.

[0047] See also Figure 1 , showing a shooting range privatization deployment mode application system in an embodiment of the present application, the system includes a central server and multiple cloud base nodes.

[0048] The central server is used to manage the range environment, user permissions, and cloud management platform access in response to management instructions, and to schedule and configure the computing resources, network resources, and storage resources of the cloud base node according to the network security tasks corresponding to the management instructions; and to display real-time dynamic information of the cloud base node executing the network security tasks. It is understandable that the central server can use any cloud base node to complete the network security tasks corresponding to the management instructions. The central server is used to comprehensively manage the range environment and accurately control user permissions, covering the allocation, adjustment, and auditing of permissions, so as to establish an orderly and secure range access and operation order.

[0049] The cloud base node is used to respond to the scheduling and configuration instructions of the central server for the network security task, and use the computing resources, network resources, and storage resources in the cloud base node to perform the network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security task. The core responsibility of multiple cloud base nodes is to efficiently perform network security training and testing tasks, and through parallel processing and collaborative operation mechanisms, they can effectively support complex and diverse security scenario simulations and attack and defense drills.

[0050] In one implementation, the central server is specifically used to set, dynamically adjust, and allocate the user's access rights and operating rights according to the user's role positioning within the organizational structure, business responsibilities, and security level requirements. It is understandable that the user rights management function of the central server can be based on the user's role positioning within the organizational structure, business responsibilities, and security level requirements, with refined rule settings and dynamic adjustment strategies, strictly allocate access rights and operating rights, ensure that each user can only carry out activities within the authorized scope, and effectively avoid security risks caused by unauthorized operations.

[0051] In one implementation, the central server includes a service delivery module, which includes a visual arrangement module, an operation management module, and a scene center module.

[0052] The visual orchestration module is used for network element management, topology management, scenario encapsulation and one-click publishing; users use visual orchestration to drag and drop components of network element devices to build a custom topology and save it as a scene, and use the scenario center to send a scenario self-test with one click to obtain an access address test. After the self-test is completed, the scene can be bound to a scenario mode such as competition, training, and teaching. It can be understood that customers use visual orchestration to drag and drop components of network element devices to build a custom topology and save it as a scene, and use the scenario center to send a scenario self-test with one click to obtain an access address test. After the self-test is completed, the scene can be bound to a variety of scenario modes such as competition, training, and teaching. Sending a scenario self-test with one click to obtain an access address test can be understood as generating an operating machine and multiple target machines, and the front end obtains the access address of an operating machine, and can use the operating machine to practice attack and defense operations. It is understandable that the visual orchestration module allows users to use the convenient drag-and-drop function of the visual interface to freely and flexibly customize the target range network architecture, carefully configure the attack scenario details, and scientifically plan the defense strategy level according to business logic, security policy orientation and personalized needs, thereby achieving a high degree of fit between the target range environment and the actual business scenarios of the enterprise and enhancing the practical effectiveness of security training and testing.

[0053] The operation management module is used to perform competition management, training management, access control and teaching management on the network security task. The operation management module can be used to create users and trainees, and to create a competition or a training task.

[0054] The scenario center module is used to perform scenario self-testing and scenario management on the attack and defense drills of the network security tasks; and customize the shooting range environment according to user needs, wherein the shooting range environment includes network structure, attack scenarios and defense strategies.

[0055] In one implementation, the visual orchestration module is specifically used to enable users to customize the target range network architecture, configure attack scenario details, and plan defense strategy levels based on business logic, security policy orientation, and personalized needs, using the convenient drag-and-drop function of the visual interface, so as to achieve a high degree of fit between the target range environment and the actual business scenarios of the enterprise, and enhance the practical effectiveness of security training and testing.

[0056] In one implementation, the central server includes a platform capability module. The platform capability module can provide capabilities for server delivery, specifically, it can provide computing services, storage services, network services, and provide computing resource virtualization, network resource virtualization, network isolation, port traffic mirroring situational awareness, and data backup capabilities for the privatized target range. The platform capability module includes computing services, storage services, and network services.

[0057] The computing service is used to provide virtualized CPU memory computing resources for the target range of the network security task.

[0058] The storage service is used to provide storage resources and data backup for the target range virtualization resources of the network security task.

[0059] The network service is used to provide network interoperability for the target range virtualization host of the network security task; wherein the network interoperability includes at least one of the following: port traffic mirroring analysis and real-time service status monitoring, VPC network isolation and security group support between target ranges, and support for VPC isolation, security group, operation audit, and two-factor authentication functions.

[0060] In one implementation, the network service is specifically used to monitor and record in real time every operation detail, every decision trajectory and every interaction behavior of the user in the shooting range environment, and through real-time data processing and intelligent feedback mechanism, it can timely present operation effectiveness evaluation, potential risk warning and optimization strategy suggestions to the user, helping the user to optimize the training path in real time.

[0061] In one implementation, each cloud base node includes a virtualization layer, which includes a computing resource pool, a storage resource pool, and a network resource pool.

[0062] The computing resource pool is used to aggregate and manage CPU and memory computing resources;

[0063] The storage resource pool is used to manage storage resources in a centralized manner;

[0064] The network resource pool is used to provide management capabilities for network resources of public networks, flat networks, and vpc networks.

[0065] In one implementation, each cloud base node includes an infrastructure module; the infrastructure module includes a SAN storage module, a physical switch, and a physical server.

[0066] The SAN storage module is used to generate a storage solution based on a network, is connected via a fiber channel, is suitable for a high-performance computing environment, and provides a data protection strategy.

[0067] The physical switch is used to provide a network lease.

[0068] The physical server is used to provide computing resources and storage resources, flexible switching between EC and replica dual mechanisms, and data encryption and backup functions to ensure the security and recoverability of training data.

[0069] In one implementation, the physical server is specifically used to use an encryption algorithm to perform real-time encryption processing on the training data to ensure the confidentiality, integrity and non-tamperability of the data during storage and transmission; at the same time, relying on intelligent backup strategies and reliable storage architecture, it supports flexible switching of multi-copy storage modes and EC erasure code technology, and ensures that the data can be accurately restored to any specified historical version in the event of accidental damage or loss of data, thereby ensuring business continuity and data asset integrity.

[0070] In one implementation, the system further includes an operation and maintenance system; the operation and maintenance system includes a platform monitoring module, a permission control module, a data warehouse, an alarm center, an operation recording module and an account management module.

[0071] The platform monitoring module is used to monitor virtual resources and physical machine resources;

[0072] The permission control module is used to control the user's access to the platform;

[0073] The data warehouse is used to store the mirror data and manage the majority of the mirror data;

[0074] The alarm center is used to push alarm information to users;

[0075] The operation recording module is used to record the user operation history;

[0076] The account management is used to add, delete, adjust and query the accounts of administrators and student users.

[0077] It is understandable that the system architecture of the target range privatization deployment mode application system includes a central server and multiple cloud base nodes. The central server is responsible for managing the target range environment and user permissions, and the cloud base nodes are used to perform the generation and start-stop work of specific network security training and test scenarios. The target range privatization deployment mode application system can realize private deployment: the target range environment is deployed in the user's private network to ensure the security and isolation of data, and support domestic trusted CPUs (Haiguang, Kunpeng, Zhaoxin, etc.) and domestic trusted operating systems (Qilin, Tongxin, etc.). The target range privatization deployment mode application system can realize user permission management: the central server has user permission management functions, and can assign corresponding access rights and operation permissions according to the roles of different users. The target range privatization deployment mode application system can realize environment customization: users can customize the target range environment according to their needs, including network structure, attack scenarios and defense strategies. The target range privatization deployment mode application system can realize real-time monitoring and feedback: the system provides real-time monitoring functions, which can record every step of the user's operation and provide instant feedback to help users evaluate the training effect. The application system of the privatized deployment model of the shooting range can achieve data security and backup: the system has data encryption and backup functions to ensure the security and recoverability of training data (supports flexible adjustment of data security policy types, including multiple copies and EC erasure codes).

[0078] It can be seen from the above technical scheme that the present application provides an application system for a shooting range privatization deployment mode, the system comprising a central server and multiple cloud base nodes; the central server is used to respond to management instructions to manage the shooting range environment, user permissions, and cloud management platform access, and, according to the network security tasks corresponding to the management instructions, the computing resources, network resources, and storage resources of the cloud base nodes are scheduled and configured; and real-time dynamic information of the cloud base nodes executing the network security tasks is displayed; the cloud base nodes are used to respond to the scheduling and configuration instructions of the central server for the network security tasks, and utilize the computing resources, network resources, and storage resources in the cloud base nodes to execute the network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security tasks. It can be seen that the application system of the privatized deployment model of the shooting range in this application has multiple significant advantages; in terms of security performance, it can effectively resolve the risk of data leakage and lay a solid foundation for enterprise network security training and testing; in terms of customization, users can schedule and configure the computing resources, network resources, and storage resources of the cloud base node, that is, customize the shooting range environment that fits the business scenario on demand, greatly improve the pertinence and accuracy of security training and testing, and accelerate the efficient implementation of security strategies in actual business. As one of the core advantages, the real-time monitoring and feedback mechanism (i.e., displaying the real-time dynamic information of the cloud base node performing the network security task) can accurately capture user operation behavior, generate in-depth analysis reports and policy guidance in real time, and help users quickly gain insight into training results, accurately locate weak links, and agilely adjust training strategies, significantly improving the efficiency of improving security skills. By utilizing the computing resources, network resources, and storage resources in the cloud base nodes to perform network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security tasks, it can protect enterprise data assets, effectively respond to potential data disasters, ensure business operation stability and continuity, and fully meet the diverse needs of enterprise network security construction, helping enterprises to move forward steadily and gain the upper hand in complex network security situations.

[0079] In other words, the application system of the target range privatization deployment model of this application has multiple significant advantages. In terms of security performance, it deploys the target range environment based on a private network, deeply integrates the trusted CPU and operating system, builds an indestructible data security barrier, effectively resolves the risk of data leakage, and lays a solid foundation for enterprise network security training and testing. In terms of customization, with the visual drag and drop function, users can customize the target range environment that suits the business scenario as needed, greatly improving the pertinence and accuracy of security training and testing, and accelerating the efficient implementation of security strategies in actual business.

[0080] As one of the core advantages, the real-time monitoring and feedback mechanism can accurately capture user operation behaviors, generate in-depth analysis reports and policy guidance in real time, and help users quickly gain insights into training results, accurately locate weak links, and agilely adjust training strategies, significantly improving the efficiency of improving safety skills. The data security and backup functions use advanced encryption technology and flexible storage strategies. While ensuring data encryption, storage and transmission, they use multiple copies and EC erasure code mechanisms to ensure data recoverability, protect enterprise data assets, effectively respond to potential data disasters, ensure business operation stability and continuity, and fully meet the diverse needs of enterprise network security construction, helping enterprises to move forward steadily and seize the initiative in complex network security situations.

[0081] It can be understood that this application has the following advantages:

[0082] 1. It provides a more secure and isolated network security training environment and supports domestically produced trusted computing. It can be deployed based on the customer's private environment and supports deployment on trusted computing CPUs and trusted computing operating systems.

[0083] 2. Allow users to customize the range environment according to specific needs to improve the pertinence and effectiveness of training. It can support the resource orchestration capabilities of multiple virtual network element devices such as firewalls, routers, switches, virtual machines, IPS, IDS, WAF, etc. Customers can customize the range scene.

[0084] 3. Real-time monitoring and feedback mechanisms help users to understand the training effect and adjust the training strategy in time. It can be combined with powerful port traffic mirroring analysis and real-time service status monitoring to provide real-time situation awareness capabilities, so that users can understand the training effect and adjust the attack and defense strategy in time.

[0085] 4. Data security and backup mechanisms ensure the security and integrity of training data.

[0086] 5. Supports hyper-convergence deployment, which saves more server resources and has stronger disaster tolerance and scalability. Supports hyper-convergence deployment. Since the hyper-convergence architecture integrates computing and storage into one device, each hyper-convergence device contains independent and complete computing and storage hardware resources, so each device constitutes an independent basic unit. Through the cluster architecture, users can use a hyper-convergence device as a unit and add more nodes to the cluster in a stacking manner, which is fast to deploy, simple to expand, and easy to manage.

[0087] 6. It has rich network and security capabilities, supports vpc isolation, security groups, operation auditing, two-factor authentication and other functions. It also has flexible and reliable data protection strategies, and flexible selection of EC and replica dual mechanisms.

[0088] Those skilled in the art should understand that the embodiments of the present application can be provided as a system or a computer program product. Therefore, the present application can adopt a complete hardware embodiment, a complete software embodiment, or a combination of software and hardware.

[0089] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the system embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the system embodiment.

[0090] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, system, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, system, commodity or device. In the absence of further restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, system, commodity or device including the elements.

[0091] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A shooting range privatization deployment mode application system, characterized in that: The system includes a central server and multiple cloud base nodes; The central server is used to manage the range environment, user permissions, and cloud management platform access in response to management instructions, and to schedule and configure the computing resources, network resources, and storage resources of the cloud base node according to the network security tasks corresponding to the management instructions; and to display the real-time dynamic information of the cloud base node executing the network security tasks; The cloud base node is used to respond to the scheduling and configuration instructions of the central server for the network security task, and utilize the computing resources, network resources, and storage resources in the cloud base node to perform network security training and testing tasks, security scenario simulation tasks, and attack and defense drills corresponding to the network security task.

2. The system according to claim 1, characterized in that The central server is specifically used to set, dynamically adjust and allocate the user's access rights and operation rights according to the user's role positioning in the organizational structure, business responsibilities and security level requirements.

3. The system according to claim 1, characterized in that The central server includes a service delivery module; The service delivery module includes a visual orchestration module, an operation management module and a scenario center module; The visual orchestration module is used for network element management, topology management, scenario encapsulation and one-click publishing. Through visual orchestration, users drag and drop components of network element devices to build a custom topology and save it as a scenario. Through the scenario center, a one-click scenario self-test is issued to obtain an access address test. After the self-test is completed, the scenario can be bound to a scenario mode for competition, training, or teaching. The operation management module is used to perform competition management, training management, access control and teaching management on the network security task; The scenario center module is used to perform scenario self-testing and scenario management on the attack and defense drills of the network security tasks; and customize the shooting range environment according to user needs, wherein the shooting range environment includes network structure, attack scenarios and defense strategies.

4. The system according to claim 3, characterized in that The visual orchestration module is specifically used for users to customize the target range network architecture, configure attack scenario details, and plan the defense strategy level based on business logic, security policy orientation and personalized needs by using the convenient drag and drop function of the visual interface, so as to achieve a high degree of fit between the target range environment and the actual business scenarios of the enterprise and enhance the practical effectiveness of security training and testing.

5. The system according to claim 1, characterized in that The central server includes a platform capability module; The platform capability module includes computing services, storage services and network services; The computing service is used to provide virtualized CPU memory computing resources for the target range of the network security task; The storage service is used to provide storage resources and data backup for the range virtualization resources of the network security task; The network service is used to provide network interoperability for the target range virtualization host of the network security task; wherein the network interoperability includes at least one of the following: port traffic mirroring analysis and real-time service status monitoring, VPC network isolation and security group support between target ranges, and support for VPC isolation, security group, operation audit, and two-factor authentication functions.

6. The system according to claim 5, characterized in that The network service is specifically used to monitor and record in real time every operation detail, every decision trajectory and every interactive behavior of the user in the shooting range environment, and through real-time data processing and intelligent feedback mechanism, it can timely present operation effectiveness evaluation, potential risk warning and optimization strategy suggestions to the user, helping the user to optimize the training path in real time.

7. The system according to claim 1, characterized in that Each cloud base node includes a virtualization layer; The virtualization layer includes a computing resource pool, a storage resource pool and a network resource pool; The computing resource pool is used to aggregate and manage CPU and memory computing resources; The storage resource pool is used to manage storage resources in a centralized manner; The network resource pool is used to provide management capabilities for network resources of public networks, flat networks, and vpc networks.

8. The system according to claim 1, characterized in that Each cloud base node includes an infrastructure module; The infrastructure module includes a SAN storage module, a physical switch and a physical server; The SAN storage module is used to generate a storage solution based on the network, connected via a fiber channel, suitable for a high-performance computing environment, and to provide a data protection strategy; The physical switch is used to provide a network lease; The physical server is used to provide computing resources and storage resources, flexible switching between EC and replica dual mechanisms, and data encryption and backup functions to ensure the security and recoverability of training data.

9. The system according to claim 1, characterized in that The physical server is specifically used to use an encryption algorithm to perform real-time encryption processing on the training data to ensure the confidentiality, integrity and non-tamperability of the data during storage and transmission; at the same time, relying on intelligent backup strategies and reliable storage architecture, it supports flexible switching of multi-copy storage modes and EC erasure code technology, and ensures that the data can be accurately restored to any specified historical version in the event of accidental damage or loss of data, thereby ensuring business continuity and data asset integrity.

10. The system according to claim 1, characterized in that The system also includes an operation and maintenance system; The operation and maintenance system includes a platform monitoring module, a permission control module, a data warehouse, an alarm center, an operation record module and an account management module; The platform monitoring module is used to monitor virtual resources and physical machine resources; The permission control module is used to control the user's access to the platform; The data warehouse is used to store the mirror data and manage the majority of the mirror data; The alarm center is used to push alarm information to users; The operation recording module is used to record the user operation history; The account management is used to add, delete, adjust and query the accounts of administrators and student users.