Electric power security system verification method and system based on machine learning and simulation attack
Through the method based on machine learning and simulated attacks, vulnerability verification and security capability evaluation of the power system is solved, and passive defense in the existing technology is difficult to deal with complex attacks, achieving efficient security assessment and protection optimization.
Patent Information
- Application Number
- CN202411951238.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-13
AI Technical Summary
The security protection of existing power systems mainly relies on passive defense measures, making it difficult to effectively deal with complex and diverse cyber attacks, and lacks active security assessment methods.
The power security system verification method based on machine learning and simulated attacks is adopted. By collecting vulnerability information, a vulnerability device library and vulnerability library are generated, a random forest algorithm is used to identify and classify vulnerabilities, conduct traffic simulation attacks, and evaluate the security capabilities of the power system.
It has realized the vulnerability verification of power security system equipment and the security capability assessment of power system, discovered potential weaknesses and vulnerabilities, formulate response strategies in advance, optimized the security protection system, and improved verification efficiency and effectiveness.
Smart Images

Figure CN119995931A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for verifying an electric power security system based on machine learning and simulated attacks. Background Art
[0002] In today's society, the power industry is undergoing profound changes and rapid development. With the continuous development of power technology and the accelerated advancement of the intelligent process, the power system is facing increasingly severe challenges in network security.
[0003] The deep digitalization and informatization of the power system has greatly improved efficiency and management, but it has also made it a potential target for cyber attacks. The entire process from energy generation, transmission, conversion to distribution and dispatch management is inseparable from massive information technology support and complex network equipment operations, which undoubtedly increases the vulnerability of the system.
[0004] Simulated attacks have emerged as a proactive means of security assessment. They comprehensively test the protection capabilities of power systems by simulating various attack methods and scenarios that may occur in the real world. For example, they simulate distributed denial of service (DDoS) attacks to test the network bandwidth and server load capacity of power systems; simulate malicious code injection attacks to examine the vulnerability detection and defense mechanisms of the system; and simulate social engineering attacks to assess personnel's security awareness and emergency response processes.
[0005] In the past, power system security protection mainly relied on traditional means such as firewalls and intrusion monitoring systems, but these passive defense measures often seem powerless in the face of increasingly complex and diverse attacks. In this context, simulated attacks are crucial to the power industry. Simulated attacks can break this passive situation, actively discover potential weaknesses and loopholes in the system, and provide strong support for formulating response strategies in advance and optimizing the security protection system. Summary of the invention
[0006] In view of the above existing problems, the present invention is proposed.
[0007] Therefore, the present invention provides a power security system verification method based on machine learning and simulated attacks, which can verify the vulnerabilities of power security system equipment and verify the safety of the security equipment itself; simulate attacks on the power system, send a large amount of vulnerability traffic, and verify the security capabilities of the power system.
[0008] In order to solve the above technical problems, the present invention provides the following technical solutions, which are a method for verifying an electric power security system based on machine learning and simulated attacks, including: collecting vulnerabilities from existing external websites and manually mined vulnerabilities, identifying and classifying the vulnerabilities by a random forest algorithm, and generating a vulnerability device library and an indexed vulnerability library for corresponding devices; obtaining device topology and fingerprint information in the target network, collecting device fingerprint information related to the network security protection system, searching the scanned device fingerprint information related to the network security protection system in the vulnerability device library, and marking the matched devices as pre-scanned device objects; performing traffic simulation attacks on the security system according to the vulnerability library script and the collected target information; processing data in combination with the random forest algorithm, and giving a system evaluation based on the attack results in multiple scenarios.
[0009] As a preferred solution of the power security system verification method based on machine learning and simulated attack described in the present invention, wherein: the vulnerability device library is a fingerprint library calculated after classifying and identifying the collected vulnerabilities, and contains fingerprint information of existing power equipment with vulnerabilities;
[0010] The vulnerability library is a vulnerability script library that is obtained by classifying and indexing the collected vulnerability scripts;
[0011] The random forest algorithm identifies and classifies vulnerabilities, including: after obtaining vulnerabilities outside the vulnerability, the random forest algorithm extracts the characteristics of the vulnerability, identifies the devices and vulnerability types involved in the vulnerability, and stores them in the vulnerability library and the vulnerability device library according to the category;
[0012] The devices involved and the vulnerability scripts are linked to perform a two-way search;
[0013] The vulnerability device library includes but is not limited to device information, device fingerprints, and vulnerability script indexes.
[0014] As a preferred solution of the power security system verification method based on machine learning and simulated attack described in the present invention, wherein: the acquisition of device topology and fingerprint information in the target network includes obtaining device fingerprint information related to the network security protection system. If the detailed information of the target security device is known, only the device specific information of the security device name, model, and IP address needs to be input, and there is no need for the asset fingerprint information scanning step; if the target security device information is unknown, the device asset fingerprint information is scanned using three methods: nmap, Masscan, and Sock;
[0015] Search for the scanned network security protection system asset fingerprint information in the vulnerability device library, use a python script to convert the fingerprint information into a message with device feature information, search the vulnerability device library to see if the current device information is contained, and store the matching results after scanning as a pre-scan device object, and perform vulnerability scans on the pre-scan device object.
[0016] As a preferred solution of the power security system verification method based on machine learning and simulated attacks described in the present invention, wherein: the vulnerability scanning of the pre-scan device object includes selecting the pre-scan device object, calling the corresponding vulnerability library script, and performing vulnerability scanning and verification on the target object; at the same time, the Zipkin framework is used to detect and track the above process, and the vulnerability library script is called as multiple concurrent sending.
[0017] As a preferred solution of the power security system verification method based on machine learning and simulated attack described in the present invention, wherein: the flow simulation attack includes extracting data packet features by a random forest algorithm, and marking the result features as labels on the data packets, preliminarily classifying the results into successful vulnerability verification and unsuccessful vulnerability verification, and marking unrecognizable data packets with feature labels and putting them into an unrecognized data packet library;
[0018] Both successful and unsuccessful vulnerability verifications are linked to the vulnerability script library and vulnerability device library, providing users with a quick search function;
[0019] After the security equipment vulnerability is verified, the attack scenarios are selected. The attack scenarios for security equipment in the power field include phishing attack scenarios, SQL injection attack scenarios, cross-site scripting attack scenarios, password brute force cracking scenarios, man-in-the-middle attack scenarios, wireless network attack scenarios, DDoS attack scenarios, zero-day vulnerability exploitation scenarios, and supply chain attack scenarios;
[0020] After the security equipment vulnerability is verified, the attack technology is retrieved, and the target object to be attacked is obtained according to the network topology; according to the selection of the attack scenario, the corresponding attack technology is retrieved.
[0021] As a preferred solution of the power security system verification method based on machine learning and simulated attack described in the present invention, the data processing method includes: training sample T = {(x1, y1), (x2, y2), ..., (x n ,y n )}, resample the sample data set T through the Bagging algorithm to form a self-service sample set θ k , set C i is the number of samples in the i-th classification. If the CART recursive classification algorithm is selected, the Gini coefficient of the tree generation method is as follows:
[0022]
[0023] Get the bootstrap sample set θ k The corresponding binary tree, where m represents the total number of categories;
[0024] The above algorithm is used to generate a binary tree. It is repeated for all sample data until all sample data are used up. The formed decision tree classifies the training data set, and then the formed multiple decision trees are combined to finally form a detection model based on random forest.
[0025] For the test samples, use the following formula to vote and select the corresponding category:
[0026]
[0027] Where c represents the category with the most votes, I(·) is the exponentiation function, K is the number of bootstrap sample sets, and a represents the out-of-bag prediction of the sample set;
[0028] For all test samples, the mixing matrix CM is obtained after calculation using the above voting formula. The element CM(i,j) represents the total number of times the test sample i is classified into category j. If i=j, it means that the current category test sample is correctly classified.
[0029] As a preferred solution of the power security system verification method based on machine learning and simulated attack described in the present invention, the system evaluation includes setting the vulnerability level high risk H i 31-50 points, medium risk M i 11-30 points, low risk L i The score is 1-11, and the specific score is set according to the severity of the vulnerability;
[0030] Assuming that there are m vulnerabilities that need to be verified in the system, then i∈[1,m], the security score calculation formula is as follows:
[0031] Sec=100-(H i γ1+M i γ2+L i γ3)
[0032] Among them, γ1, γ2, and γ3 are the number of three types of vulnerabilities, high, medium, and low, respectively. The comprehensive score of vulnerability verification is as follows:
[0033]
[0034] Where P is the score, k is the total number of systems, j∈[1,k], Sec j is the safety score of system j, q is the weight, and x is the number of systems in the same score range.
[0035] As a preferred solution of the power security system verification system based on machine learning and simulated attacks described in the present invention, it includes: a vulnerability management module, an attack scenario management module, an information collection module, a security equipment vulnerability scanning module, a simulated scenario attack module, and a data processing module;
[0036] The vulnerability management module stores and manages vulnerabilities, including receiving vulnerabilities from an external vulnerability database or external manual submissions, and storing the vulnerability library and vulnerability device library processed by the data processing module;
[0037] The attack scenario management module is responsible for adding, deleting, modifying and checking attack scenarios;
[0038] The information collection module obtains detailed information about the network and devices, collects specific information about vulnerability security devices and network devices, and also includes a network topology information acquisition module and a device fingerprint collection module;
[0039] The security equipment vulnerability scanning module is a vulnerability detection module specifically for security system equipment, which detects and verifies whether the security equipment has 0day or 1day vulnerabilities;
[0040] The simulated scenario attack module is responsible for simulating attacks on the security system in specific scenarios to test the security of security equipment. It also includes four modules: attack scenario selection module, attack method selection module, attack path selection module, and scenario simulation attack module.
[0041] The data processing module uses a random forest algorithm to identify and classify and group various types of data for storage.
[0042] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, steps of a method for verifying an electric power security system based on machine learning and simulated attacks are implemented.
[0043] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of a method for verifying a power security system based on machine learning and simulated attacks are implemented.
[0044] Beneficial effects of the present invention: This method adopts a dual verification mode of verifying the device's own vulnerabilities and the traffic passing through the vulnerabilities to detect the protection capabilities of the technical protection system. At the same time, with the help of deep learning algorithms, the vulnerability data and traffic data are processed to achieve the automatic generation of vulnerabilities and the automation of result verification. Not only does it have better verification capabilities, but it also has higher verification efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:
[0046] Figure 1 A schematic flow chart of a method for verifying an electric power security system based on machine learning and simulated attacks provided in accordance with an embodiment of the present invention.
[0047] Figure 2 A random forest algorithm flow chart of a power security system verification method based on machine learning and simulated attacks provided in one embodiment of the present invention.
[0048] Figure 3 A schematic diagram of the structure of a power security system verification system based on machine learning and simulated attacks provided by one embodiment of the present invention.
[0049] Figure 4 Schematic diagram of working modules of a power security system verification system based on machine learning and simulated attacks provided by an embodiment of the present invention DETAILED DESCRIPTION
[0050] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0051] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0052] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or selective embodiment that is mutually exclusive with other embodiments.
[0053] The present invention is described in detail with reference to schematic diagrams. When describing the embodiments of the present invention, for the sake of convenience, the cross-sectional diagrams showing the device structure will not be partially enlarged according to the general scale, and the schematic diagrams are only examples, which should not limit the scope of protection of the present invention. In addition, in actual production, the three-dimensional dimensions of length, width and depth should be included.
[0054] At the same time, in the description of the present invention, it should be noted that the directions or positional relationships indicated by the terms "upper, lower, inner and outer" are based on the directions or positional relationships shown in the drawings, which are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore cannot be understood as limiting the present invention. In addition, the terms "first, second or third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0055] In the present invention, unless otherwise clearly specified and limited, the terms "install, connect, connect" should be understood in a broad sense, for example: it can be a fixed connection, a detachable connection or an integral connection; it can also be a mechanical connection, an electrical connection or a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0056] Example 1, reference Figure 1 and Figure 2 , which is the first embodiment of the present invention, provides a power security system verification method based on machine learning and simulated attacks, including:
[0057] S1: Collect vulnerabilities from existing external websites and manually discovered vulnerabilities, identify and classify them using the random forest algorithm, and generate a vulnerability device library and an indexed vulnerability library for the corresponding devices.
[0058] Furthermore, the vulnerability device library is a fingerprint library calculated after classifying and identifying the collected vulnerabilities, and contains fingerprint information of existing power equipment with vulnerabilities;
[0059] The vulnerability library is a vulnerability script library that is obtained by classifying and indexing the collected vulnerability scripts;
[0060] The random forest algorithm identifies and classifies vulnerabilities, including: after obtaining vulnerabilities outside the vulnerability, the random forest algorithm extracts the characteristics of the vulnerability, identifies the devices and vulnerability types involved in the vulnerability, and stores them in the vulnerability library and the vulnerability device library according to the category;
[0061] The devices involved and the vulnerability scripts are linked to perform a two-way search;
[0062] The vulnerability device library includes but is not limited to device information, device fingerprints, and vulnerability script indexes.
[0063] It should be noted that external vulnerability scripts are vulnerability scripts contained in external vulnerability libraries such as CNVD, CVE, CNNVD, and vulnerability scripts submitted by manual mining.
[0064] S2: Obtain the device topology and fingerprint information in the target network, collect the device fingerprint information related to the network security protection system, search for the scanned device fingerprint information related to the network security protection system in the vulnerability device library, and mark the matched device as a pre-scan device object.
[0065] Furthermore, to obtain device fingerprint information related to the network security protection system, if the target security device details are known, only the device specific information of the security device name, model, and IP address needs to be entered, and there is no need for the asset fingerprint information scanning step; if the target security device information is unknown, three methods, nmap, Masscan, and Sock, are used to scan the device asset fingerprint information;
[0066] Search for the scanned network security protection system asset fingerprint information in the vulnerability device library, use a python script to convert the fingerprint information into a message with device feature information, search the vulnerability device library to see if the current device information is contained, and store the matching results after scanning as a pre-scan device object, and perform vulnerability scans on the pre-scan device object.
[0067] It should be noted that the network security protection system-related equipment is protection equipment for enterprise, government and other networks, such as DLP, WAF, antivirus and APT, etc.
[0068] It should be noted that the vulnerability scanning of the pre-scan device object includes selecting the pre-scan device object, calling the corresponding vulnerability library script, and performing vulnerability scanning verification on the target object; at the same time, the Zipkin framework is used to detect and track the above process, and the vulnerability library script is called to send multiple concurrently.
[0069] S3: Conduct traffic simulation attacks on the security system based on the vulnerability library script and the collected target information.
[0070] Furthermore, the random forest algorithm extracts data packet features and uses the resulting features as labels to preliminarily classify the results into successful vulnerability verification and unsuccessful vulnerability verification, and labels unrecognizable data packets with features and puts them into the unrecognized data packet library;
[0071] Both successful and unsuccessful vulnerability verifications are linked to the vulnerability script library and vulnerability device library, providing users with a quick search function;
[0072] After the security equipment vulnerability is verified, the attack scenarios are selected. The attack scenarios for security equipment in the power field include phishing attack scenarios, SQL injection attack scenarios, cross-site scripting attack scenarios, password brute force cracking scenarios, man-in-the-middle attack scenarios, wireless network attack scenarios, DDoS attack scenarios, zero-day vulnerability exploitation scenarios, and supply chain attack scenarios;
[0073] After the security equipment vulnerability is verified, the attack technology is retrieved, and the target object to be attacked is obtained according to the network topology; according to the selection of the attack scenario, the corresponding attack technology is retrieved.
[0074] S4: Combine the random forest algorithm to process the data and give a system evaluation based on the attack results in multiple scenarios.
[0075] Furthermore, the essence of random forest (RF) is a classifier algorithm with high accuracy, which is mainly composed of multiple decision trees (DT), and can effectively tolerate noise signals and outliers contained in the original signal. Each decision tree T(i) of RF will produce a result R(i), which is the classification of the original signal. Then, each result R(i) is voted, and the R(i) with the most votes is the final classification result. The RF algorithm commonly uses the Bagging resampling ensemble algorithm. Compared with a single classifier, the Bagging ensemble method is to perform multi-classification training on multiple training samples, obtain multi-classification clustering results, and finally obtain the classification result.
[0076] according to Figure 1 As shown, the basic steps of the RF algorithm are:
[0077] Step 1: Sample collection: training sample T = {(x1,y1),(x2,y2),…,(x n ,y n )}, resample the sample data set T through the Bagging algorithm to form a self-service sample set θ k ;
[0078] Step 2: DT generation: In the DT model, {h(a,θ k ,k=1,2,…,K)}, select CART recursive classification algorithm, and get the bootstrap sample set θ k The corresponding binary tree. Set C i is the number of samples in the i-th classification. If the CART recursive classification algorithm is selected, the Gini coefficient of the tree generation method is as follows:
[0079]
[0080] Get the bootstrap sample set θ k The corresponding binary tree, where m represents the total number of categories.
[0081] Step 3, model generation: Repeat steps 1 and 2 until all feature attributes are used up and the formed DT can accurately classify the training data set. Then combine the multiple DTs to finally form a detection model based on RF.
[0082] Step 4: Category generation: For the test samples, use the following formula to vote and select the corresponding category:
[0083]
[0084] Where c represents the category with the most votes, I(·) is the exponentiation function, K is the number of bootstrap sample sets, and a represents the out-of-bag prediction of the sample set;
[0085] Step 5 Category Verification: For all test samples, the mixing matrix CM is obtained after the above voting formula is calculated. Its element CM(i,j) represents the total number of times the test sample i is classified into category j. If i=j, it means that the test sample of this category is correctly classified.
[0086] The above is the model of the random forest algorithm used in this patent, which can greatly enhance the ability of vulnerability processing and traffic processing, reduce the pressure of result auditing, improve the efficiency of the final verification effect evaluation, and ultimately improve the overall efficiency and stability of the system.
[0087] Furthermore, we set the vulnerability level to high risk. i 31-50 points, medium risk M i 11-30 points, low risk L i The score is 1-11, and the specific score is set according to the severity of the vulnerability;
[0088] Assuming that there are m vulnerabilities that need to be verified in the system, then i∈[1,m], the security score calculation formula is as follows:
[0089] Sec=100-(H i γ1+M i γ2+L i γ3)
[0090] Among them, γ1, γ2, and γ3 are the number of three types of vulnerabilities, high, medium, and low. The Sec range is set to 90-100 for excellent, 80-89 for good, 60-79 for passing, and 0-59 for failing. For example, the command execution of a high-risk vulnerability is generally 41. If such a high-risk vulnerability appears, the system will directly judge it as failing, which is very dangerous.
[0091] Since the entire power system contains a large number of systems, a comprehensive vulnerability verification score is required. In order to enhance the verification capability of medium and high risks, the Sec of each device is weighted. The weights are as follows:
[0092] 90-100 points: 0.2
[0093] 80-89 points: 0.5
[0094] 60-79 points: 1
[0095] 0-59 points: 1.2
[0096] The combined validation score is as follows:
[0097]
[0098] Where P is the score, k is the total number of systems, j∈[1,k], Sec j is the security score of system j, q is the weight, and x is the number of systems in the same score range. When there are a large number of devices that need security verification, the above formula will amplify the impact of high risk and medium risk.
[0099] Example 2, reference Figure 3 , which is an embodiment of the present invention, provides a power security system verification method based on machine learning and simulated attacks. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through experiments.
[0100] Different from traditional verification technology, based on simulated attack technology, two steps are proposed to verify the power security protection system. First, the vulnerability of the power security system equipment is verified to verify the security of the security equipment itself; second, simulate attacks are carried out on the power system, sending a large amount of vulnerability traffic to verify the security capabilities of the power system. Figure 3 As shown, the method includes:
[0101] First, a vulnerability database is established through the vulnerability management module, and external public vulnerability databases such as CNVD, CVE, CNNVD, etc. are connected. At the same time, vulnerability databases of major security vendors are connected according to actual needs and actual capabilities. After obtaining the vulnerability script information, the sample data set D = {(x1, y1), (x2, y2), …, (x n ,y n )}, vulnerability information x is used as input, y is the self-selected output data and is a continuous variable. The Bagging algorithm is used for resampling, M times of self-sampling in the training sample data set, and a self-service sample set δ is generated. m, where m=1,2,…,M. Use the CART algorithm to find the optimal binary decision tree for the self-service sample set, and repeat sampling and decision tree generation to generate the final random forest model. For the generated test cases, classification detection is performed according to the formula, and the correctness of the generated matrix is confirmed. By establishing the above RF-based classification model and combining it with the python language programming algorithm, the vulnerabilities are automatically classified according to the vulnerability information to generate a vulnerability device library and a vulnerability library with indexes for the corresponding devices; the vulnerability device library is a fingerprint library calculated after the collected vulnerabilities are classified and identified, which contains the fingerprint information of existing power equipment with vulnerabilities; the vulnerability library is a vulnerability script library that has been classified and indexed by the collected vulnerability scripts;
[0102] Obtain the device topology and fingerprint information in the target network, and collect device fingerprint information related to the network security protection system. The network security protection system related equipment is protection equipment for enterprise, government and other networks, such as DLP, WAF, antivirus and APT, etc. The present invention includes but is not limited to two collection methods-real interaction and traffic detection. Since the information collection module has a traffic detection function, most of the information that can be detected will be automatically filled in after the traffic detection. The system should also provide a method for manually inputting information, and manual input of information includes direct import in the form of Excel tables and manual filling in of blanks one by one. There are no strict format requirements for Excel tables, but they need to be stored in the form of key-value pairs to facilitate the system module to scan and fill in the information. If the information after the traffic detection meets the minimum collection requirements, the next step of the attack can be carried out; otherwise, it is necessary to repeat the traffic detection or manually fill in the required collection information through consultation.
[0103] After the information collection module obtains enough information, it is necessary to first verify whether the protection device itself has vulnerabilities. Through the security device vulnerability scanning module, the fingerprint information of the network security protection system-related devices obtained by scanning is searched in the vulnerability device library, and the matched devices are marked as pre-scan device objects; then the pre-scan device objects are scanned for vulnerabilities; the vulnerability scan is mainly to verify whether the network security protection system-related devices themselves have vulnerabilities. If there is a vulnerability, the device vulnerability is successfully detected, the danger level of the vulnerability is released, a warning is issued, and the vulnerability is repaired.
[0104] If there are no vulnerabilities in the security equipment, use the simulated scenario attack module to verify the capabilities of the security equipment.
[0105] Select the corresponding attack scenario. The attack scenarios mainly include most of the attack methods that network security can encounter. The attack scenarios for power security equipment include phishing attack scenarios, SQL injection attack scenarios, cross-site scripting attack (XSS) scenarios, password brute force cracking scenarios, man-in-the-middle attack scenarios, wireless network attack scenarios, DDoS attack scenarios, zero-day vulnerability exploitation scenarios, and supply chain attack scenarios. Select scenarios based on actual conditions, or select attacks one by one.
[0106] After the attack scenario is selected, select the corresponding attack method. For example, if you select the SQL injection attack scenario, you can choose the full flow injection attack, or you can choose a single attack method such as joint query injection, error-induced injection, Boolean blind injection, time delay injection, second-order injection, injection based on stored procedures, and out-of-band injection, etc. Then, according to the topology structure, set the attack path, such as the attack object, the path through which the specific traffic passes through the router and the security equipment, and then start simulating the attack.
[0107] In the full-flow simulation attack process, since a large amount of vulnerability verification traffic is sent at one time, the traffic returned by the target needs to be processed and classified. The RF-based traffic classification algorithm is used. According to the algorithm, after the return traffic feature classification, the python algorithm is used to match the recognition algorithm to obtain the preliminary results of the return traffic, and the corresponding traffic in this scanning process is marked in the database.
[0108] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
[0109] Embodiment 3, the third embodiment of the present invention, is different from the first two embodiments in that:
[0110] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.
[0111] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0112] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0113] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0114] Example 4, reference Figure 3 and Figure 4 , which is an embodiment of the present invention, provides a power security system verification system based on machine learning and simulated attacks, which is characterized by:
[0115] Vulnerability management module is mainly responsible for comprehensive storage and management of vulnerabilities. Its functions include receiving information from external vulnerability databases and external manually submitted vulnerabilities. At the same time, it will also effectively manage the vulnerability library and vulnerability device library processed by the storage data processing module to achieve accurate control and efficient processing of vulnerabilities.
[0116] Furthermore, it stores vulnerabilities obtained from external websites such as CVE, CNVD, CNNVD and other vulnerability libraries, as well as undisclosed vulnerabilities such as 0day or 1day submitted by other users after bounties. It manages the vulnerability library and device vulnerability library generated after classification and identification of the original vulnerability library. It also stores and manages the poc script library.
[0117] The attack scenario management module includes adding attack scenarios, deleting attack scenarios, modifying attack scenarios, and querying existing attack scenarios. It is convenient for users to better view and manage attack scenarios, and this module can provide strong support for other modules.
[0118] Information collection module,The information collection module undertakes the important task of obtaining detailed information about the network and devices. It is committed to collecting specific information about vulnerability security devices and network devices, including the network topology information acquisition module, which is used to accurately obtain the network topology structure, and the device fingerprint acquisition module, which is used to fully grasp the device characteristics.
[0119] Furthermore, two methods, active and passive, are used to send traffic for device fingerprint collection. The active method is to actively send a detection data packet and obtain device fingerprint information through the returned data packet. The passive method is to install an agent in the other party's device to detect past traffic and obtain device fingerprint information.
[0120] In addition to active and passive network communication methods, in order to obtain the network topology, you can also manually enter it through inquiries, on-site inspections, and thus obtain a more accurate network topology.
[0121] The security equipment vulnerability scanning module is a vulnerability detection module specifically for security system equipment. It focuses on in-depth detection and verification of security equipment such as WAF and DLP to confirm whether these devices have 0day or 1day vulnerabilities, so as to discover potential risks in advance, ensure the stability and reliability of the security system, and improve overall security.
[0122] The simulated scenario attack module is mainly responsible for conducting simulated attacks on the security system in specific scenarios to test the security of security equipment. It consists of four key modules: the attack scenario selection module, which is used to determine the specific environment of the attack; the attack method selection module, which determines the attack method to be adopted; the attack path selection module, which plans the attack route; and the scenario simulation attack module, which implements specific simulated attack operations.
[0123] The data processing module uses the random forest algorithm to identify and classify and group various types of data, including external vulnerability script data, returned data packet data, etc.
[0124] Furthermore, the random forest algorithm is used to achieve the functions of feature extraction and classification. It is mainly used in the following two scenarios: First, when dealing with vulnerabilities, two databases are generated by extracting and classifying vulnerability features, namely a new vulnerability database and a vulnerability device database; second, when dealing with data packets, preliminary verification results can be obtained by extracting features and classifying data packets.
[0125] The data processing module is mainly designed to reduce manual pressure, realize autonomy and automation capabilities, and improve the overall efficiency of the system.
[0126] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A power security system verification method based on machine learning and simulated attacks, characterized by: include, Collect vulnerabilities from existing external websites and manually discovered vulnerabilities, identify and classify them using the random forest algorithm, and generate a vulnerability device library and an indexed vulnerability library for the corresponding devices; Obtain the device topology and fingerprint information in the target network, collect device fingerprint information related to the network security protection system, search for the scanned device fingerprint information related to the network security protection system in the vulnerability device library, and mark the matched device as a pre-scan device object; Conduct traffic simulation attacks on security systems based on vulnerability library scripts and collected target information; The data is processed using the random forest algorithm, and a system evaluation is given based on the attack results in multiple scenarios.
2. The power security system verification method based on machine learning and simulated attack according to claim 1, characterized in that: The vulnerability device library is a fingerprint library calculated after classifying and identifying the collected vulnerabilities, and contains fingerprint information of existing power equipment with vulnerabilities; The vulnerability library is a vulnerability script library that is obtained by classifying and indexing the collected vulnerability scripts; The random forest algorithm identifies and classifies vulnerabilities, including: after obtaining vulnerabilities outside the vulnerability, the random forest algorithm extracts the characteristics of the vulnerability, identifies the devices and vulnerability types involved in the vulnerability, and stores them in the vulnerability library and the vulnerability device library according to the category; The devices involved and the vulnerability scripts are linked to perform a two-way search; The vulnerability device library includes but is not limited to device information, device fingerprints, and vulnerability script indexes.
3. The power security system verification method based on machine learning and simulated attack as claimed in claim 2, characterized in that: The acquisition of the device topology and fingerprint information in the target network includes obtaining the device fingerprint information related to the network security protection system. If the detailed information of the target security device is known, only the device specific information of the security device name, model, and IP address needs to be entered, and there is no need for the asset fingerprint information scanning step; if the target security device information is unknown, the device asset fingerprint information is scanned using three methods: nmap, Masscan, and Sock; Search for the scanned network security protection system asset fingerprint information in the vulnerability device library, use a python script to convert the fingerprint information into a message with device feature information, search the vulnerability device library to see if the current device information is contained, and store the matching results after scanning as a pre-scan device object, and perform vulnerability scans on the pre-scan device object.
4. The power security system verification method based on machine learning and simulated attack as claimed in claim 3, characterized in that: The vulnerability scanning of the pre-scan device object includes selecting the pre-scan device object, calling the corresponding vulnerability library script, and performing vulnerability scanning verification on the target object; at the same time, using the Zipkin framework to detect and track the above process, calling the vulnerability library script as multiple concurrent sending.
5. The method for verifying a power security system based on machine learning and simulated attacks as claimed in claim 4, characterized in that: The traffic simulation attack includes extracting data packet features by a random forest algorithm, and marking the result features as labels on the data packets, preliminarily classifying the results into successful vulnerability verification and unsuccessful vulnerability verification, and marking unrecognizable data packets with feature labels and putting them into an unrecognized data packet library; Both successful and unsuccessful vulnerability verifications are linked to the vulnerability script library and vulnerability device library, providing users with a quick search function; After the security equipment vulnerability is verified, the attack scenarios are selected. The attack scenarios for security equipment in the power field include phishing attack scenarios, SQL injection attack scenarios, cross-site scripting attack scenarios, password brute force cracking scenarios, man-in-the-middle attack scenarios, wireless network attack scenarios, DDoS attack scenarios, zero-day vulnerability exploitation scenarios, and supply chain attack scenarios; After the security equipment vulnerability is verified, the attack technology is retrieved, and the target object to be attacked is obtained according to the network topology; according to the selection of the attack scenario, the corresponding attack technology is retrieved.
6. The power security system verification method based on machine learning and simulated attack as claimed in claim 5, characterized in that: The data processing method includes: training sample T = {(x1, y1), (x2, y2), ..., (x n ,y n )}, resample the sample data set T through the Bagging algorithm to form a self-service sample set θ k , set C i is the number of samples in the i-th classification. If the CART recursive classification algorithm is selected, the Gini coefficient of the tree generation method is as follows: Get the bootstrap sample set θ k The corresponding binary tree, where m represents the total number of categories; The above algorithm is used to generate a binary tree. It is repeated for all sample data until all sample data are used up. The formed decision tree classifies the training data set, and then the formed multiple decision trees are combined to finally form a detection model based on random forest. For the test samples, use the following formula to vote and select the corresponding category: Where c represents the category with the most votes, I(·) is the exponentiation function, K is the number of bootstrap sample sets, and a represents the out-of-bag prediction of the sample set; For all test samples, the mixing matrix CM is obtained after calculation by the above voting formula. The element CM(i,j) represents the total number of times the test sample i is classified into category j. If i=j, it means that the current category test sample is correctly classified.
7. The method for verifying a power security system based on machine learning and simulated attacks as claimed in claim 6, characterized in that: The system evaluation includes setting the vulnerability level high risk H i 31-50 points, medium risk M i 11-30 points, low risk L i The score is 1-11, and the specific score is set according to the severity of the vulnerability; Assuming that there are m vulnerabilities that need to be verified in the system, then i∈[1,m], the security score calculation formula is as follows: Sec=100-(H i ·γ1+M i ·γ2+L i ·γ3) Among them, γ1, γ2, and γ3 are the number of three types of vulnerabilities, high, medium, and low, respectively. The comprehensive score of vulnerability verification is as follows: Where P is the score, k is the total number of systems, j∈[1,k], Sec j is the safety score of system j, q is the weight, and x is the number of systems in the same score range.
8. A system using the power security system verification method based on machine learning and simulated attack as claimed in any one of claims 1 to 7, characterized in that: It includes vulnerability management module, attack scenario management module, information collection module, security equipment vulnerability scanning module, simulation scenario attack module and data processing module; The vulnerability management module stores and manages vulnerabilities, including receiving vulnerabilities from an external vulnerability database or external manual submissions, and storing the vulnerability library and vulnerability device library processed by the data processing module; The attack scenario management module is responsible for adding, deleting, modifying and checking attack scenarios; The information collection module obtains detailed information about the network and devices, collects specific information about vulnerability security devices and network devices, and also includes a network topology information acquisition module and a device fingerprint collection module; The security equipment vulnerability scanning module is a vulnerability detection module specifically for security system equipment, which detects and verifies whether the security equipment has 0day or 1day vulnerabilities; The simulated scenario attack module is responsible for simulating attacks on the security system in specific scenarios to test the security of security equipment. It also includes four modules: attack scenario selection module, attack method selection module, attack path selection module, and scenario simulation attack module. The data processing module uses a random forest algorithm to identify and classify and group various types of data for storage.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Network attack and defense strategy generation method and device, equipment and storage medium
CN120750603A