Large-scale network node scene construction method and system based on network target range

By calculating the vulnerability correlation and business affinity between nodes in the network shooting range, optimizing the network topology structure, and optimizing the node operating environment through resource utilization prediction and stress testing, the problem that network node scenario structure in the existing technology is difficult to meet large-scale needs, and an efficient and real network node scenario structure is achieved.

CN119996079AActive Publication Date: 2025-05-13JIANGSU BOZHI SOFTWARE TECH CO LTD

Patent Information

Application Number
CN202510450817.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-05-13
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

The network node scenario structure in existing network shooting ranges is difficult to meet large-scale needs, and the vulnerability correlation and business correlation between nodes are insufficiently considered, resulting in low scenario authenticity and resource utilization efficiency.

Method used

A large-scale network node scenario construction method based on network shooting range is adopted, and the vulnerability correlation between nodes is calculated, the offensive and defense levels are divided, the node distribution map is generated, the vulnerability chain propagation coefficient is matched, and the target network node template is filtered. Then, the network topology is optimized using graph theory clustering algorithm, the initial topology is optimized based on business affinity, and the target topology is generated. Finally, through resource utilization index prediction and stress testing, the node operation environment is optimized, vulnerability programs are implanted, and abnormal detection and repair are carried out.

Benefits of technology

It realizes the automated construction of large-scale network node scenarios, ensures the authenticity of the scene and resource utilization efficiency, and improves the training effect of network offensive and defense confrontation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996079A_ABST
    Figure CN119996079A_ABST
Patent Text Reader

Abstract

The invention provides a large-scale network node scene construction method and system based on a network target range, and relates to the technical field of network security, and the method comprises the steps: dividing network nodes into a plurality of attack and defense levels through calculating the vulnerability association degree between the nodes, and screening a target network node template based on a vulnerability chain-type propagation coefficient. Secondly, optimizing a network topology structure by adopting a graph theory clustering algorithm, and constructing a connection relation between nodes based on service affinity; and finally, according to the resource utilization rate index, constructing a node operation environment, deploying network services, implanting a vulnerability program and carrying out anomaly detection and repair, and finally generating a large-scale network node scene meeting resource optimization scheme constraints. According to the method, the large-scale network target range with a complex topological structure and a real vulnerability environment can be automatically constructed, and the efficiency and authenticity of network security attack and defense drilling are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to network security technology, and in particular to a large-scale network node scene construction method and system based on a network target range. Background Art

[0002] As an important platform for network security research, the authenticity and scale of the network node scenario construction in the network range directly affect the training effect of attack and defense confrontation. The network node scenario construction in the existing network range mainly relies on manual configuration, which is difficult to meet the needs of large-scale scenario construction, and the vulnerability correlation and business correlation between nodes are not considered enough.

[0003] As the scale of network target ranges continues to expand, the number of network nodes is growing exponentially. Traditional manual configuration methods have problems such as large workload and low configuration efficiency. At the same time, due to the lack of quantitative analysis of vulnerability propagation characteristics and business affinity between nodes, it is difficult to ensure the authenticity of the constructed scenario, which affects the effectiveness of network attack and defense confrontation.

[0004] The existing network node scene construction methods mainly focus on the functional realization of a single node, and do not consider the correlation between nodes and resource utilization efficiency enough, making it difficult to achieve adaptive optimization of network topology and reasonable allocation of resources. Therefore, there is an urgent need for a method that can automatically construct large-scale network node scenes and ensure the authenticity of the scenes and resource utilization efficiency. Summary of the invention

[0005] The embodiments of the present invention provide a method and system for constructing a large-scale network node scenario based on a network target range, which can solve the problems in the prior art.

[0006] According to a first aspect of the embodiments of the present invention, A method for constructing a large-scale network node scenario based on a network range is provided, comprising: Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; A graph clustering algorithm is used to calculate the node distribution density threshold and hierarchically optimize the network topology type in the network node scenario construction requirements to obtain the initial network topology structure. The target network node template is used to generate a network node instance through attribute mapping. The connection relationship between network node instances is constructed based on the communication protocol information between nodes. The communication characteristics between network node instances are extracted and the business affinity is calculated. The initial network topology structure is optimized based on the business affinity to generate the target network topology structure. Generate resource utilization indicators according to the target network topology structure, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from the preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment, and perform anomaly detection and repair according to the fault feature sequences, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.

[0007] In an optional embodiment, Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node templates including: According to the vulnerability correlation between nodes, a node correlation graph is constructed. The node correlation graph is divided based on the community discovery algorithm to generate an attack and defense level node distribution graph. The vulnerability exploitation chain is introduced and the trigger probability of adjacent vulnerabilities and the attack chain length attenuation coefficient are calculated. The vulnerability intensity values ​​at the corresponding positions in the attack and defense level node distribution graph are matched. The candidate network node template with the minimum matching value is selected as the target network node template. Specifically, it includes: Obtain vulnerability attribute information of network nodes to generate node vulnerability feature vectors, calculate distance decay function values ​​based on the number of communication hops between nodes, perform tensor operations on the node vulnerability feature vectors and the distance decay function values ​​to obtain node vulnerability combination matrices, and calculate vulnerability correlations between nodes in network node scenario construction requirements based on the node vulnerability combination matrix; The vulnerability correlation degree is used as the edge weight to construct a node correlation graph, the node correlation graph is iteratively divided using a community discovery algorithm, the network nodes are divided into multiple attack and defense levels, and the level vulnerability strength value is calculated for each attack and defense level; Generate an attack and defense level node distribution graph based on the level position relationship of the attack and defense levels and the level vulnerability strength values, wherein the nodes represent the attack and defense levels, and the connecting edges between the nodes represent the vulnerability strength relationship between the levels; Extract candidate network node templates from a preset network node template library, establish connection relationships between vulnerabilities based on vulnerability features in the candidate network node templates through system state requirements, state changes, and attack entry types in the vulnerability features, introduce system state change continuity as a screening condition for vulnerability exploitation chains, and combine the cascade trigger probability of the attack chain with the length attenuation coefficient to calculate the vulnerability chain propagation coefficient; The vulnerability chain propagation coefficient is matched with the vulnerability strength value at the corresponding position in the attack and defense hierarchical node distribution map to obtain a propagation coefficient deviation value, and the hierarchical vulnerability strength change after deployment is calculated based on the candidate network node template. The weighted sum of the propagation coefficient deviation value and the hierarchical vulnerability strength change is determined as the matching value, and the candidate network node template with the minimum matching value is selected as the target network node template.

[0008] In an optional embodiment, The connection relationship between vulnerabilities is established through the system state requirements, state changes and attack entry types in the vulnerability characteristics. The continuity of system state changes is introduced as the screening condition for the vulnerability exploit chain. The cascade trigger probability of the attack chain is combined with the length attenuation coefficient. The vulnerability chain propagation coefficient is calculated, including: Extract vulnerability features from the candidate network node template, wherein the vulnerability features include system state requirements triggered by the vulnerability, system state changes after the vulnerability is exploited, and attack entry types of the vulnerability exploitation, and construct a vulnerability feature vector; Perform feature matching according to the system state requirements, system state changes, and attack entry types in the vulnerability feature vector, and establish a connection relationship between the two vulnerabilities when the system state change of the first vulnerability meets the system state requirements of the second vulnerability and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability; Building a vulnerability dependency graph based on the connection relationship, identifying a vulnerability exploit chain path in the vulnerability dependency graph using a depth-first search method, screening the vulnerability exploit chain path according to the continuity of system state changes in the vulnerability feature vector, and generating a vulnerability exploit chain; Based on the number of nodes in the vulnerability exploit chain, the connection distance between adjacent nodes is calculated, the path length of the vulnerability exploit chain is calculated according to the connection distance, and the path length is substituted into an exponential decay function to obtain an attack chain length decay coefficient of the vulnerability exploit chain; For adjacent vulnerabilities in the vulnerability exploitation chain, the triggering probabilities of the adjacent vulnerabilities are multiplied in sequence according to the connection order of the vulnerabilities in the vulnerability exploitation chain to obtain the cascade triggering probability of the vulnerability exploitation chain, and the cascade triggering probability is multiplied by the attack chain length attenuation coefficient to obtain the vulnerability chain propagation coefficient; An attack path graph is constructed based on the vulnerability feature vector and the vulnerability exploitation chain, and the vulnerability exploitation chain is mapped to an attack path. The number of successes of the attack path is counted through multiple simulations, and the calculation parameters of the trigger probability and the attack chain length attenuation coefficient are optimized using the number of successes of the attack path. The vulnerability chain propagation coefficient is recalculated using the optimized parameters to obtain the final vulnerability chain propagation coefficient.

[0009] In an optional embodiment, The graph clustering algorithm is used to calculate the node distribution density threshold and the network topology type in the network node scenario construction requirements is hierarchically optimized to obtain the initial network topology structure. The target network node template is used to generate a network node instance through attribute mapping. The connection relationship between network node instances is constructed based on the communication protocol information between nodes. The communication characteristics between network node instances are extracted and the business affinity is calculated. The initial network topology structure is optimized based on the business affinity. The target network topology structure is generated, including: A distance matrix is ​​constructed according to the Euclidean distance between nodes. A graph clustering algorithm is used based on the distance matrix to calculate the local density and relative density of nodes. A density threshold is set in combination with the network node scenario construction requirements. The local density and relative density of the nodes are normalized to obtain the node comprehensive density value. The nodes are hierarchically divided according to the network topology layering requirements. The topological connection relationship of the nodes in each layer is determined according to the comprehensive density value. The initial network topology structure that meets the hierarchical constraints is obtained through iterative optimization. Extracting hardware configuration information and software configuration information from the target network node template, constructing a static attribute feature set and a dynamic attribute feature set, mapping the static attribute feature set to the hardware parameters of the node instance based on the feature mapping rule, mapping the dynamic attribute feature set to the software parameters of the node instance, and generating a network node instance; Design a protocol feature tensor, encode the communication protocol information between node instances into a multi-dimensional feature tensor, use a tensor decomposition method to extract implicit factors of the protocol features, build a protocol similarity measurement model based on the implicit factors, calculate the protocol compatibility matrix between node instances, and determine the connection relationship between node instances according to the compatibility threshold; A sliding time window is used to extract the business traffic time series characteristics between network node instances. The business traffic time series characteristics are analyzed based on the long short-term memory network to obtain the business traffic prediction results. A business dependency graph is constructed through service call chain analysis. The node association characteristics in the business dependency graph are extracted in combination with the graph attention network. The node resource utilization characteristics are counted based on resource monitoring data. The business traffic prediction results, node association characteristics and resource utilization characteristics are fused in multiple dimensions to calculate the business affinity. Taking business affinity as the state space and the change of connection relationship between network node instances as the action space, a reward function that considers node processing capacity constraints, link bandwidth constraints and end-to-end delay constraints is constructed. The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topology connection plan is output. The initial network topology structure is optimized through the optimal topology connection plan to generate the target network topology structure.

[0010] In an optional embodiment, The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topological connection solution is output, including: A dual network architecture of value function network and policy network is constructed. The temporal difference error is used to guide the priority sampling of the experience pool and the parameters are optimized based on the policy trust region constraint. At the same time, the advantage function is used to adjust the improvement direction of the policy network and the state access distribution is introduced to guide the training of the value function network. When the optimization converges, the sequence with the highest action probability is output as the optimal topological connection solution, which includes: Obtaining the business affinity matrix and the connection state matrix of the initial network topology structure, and constructing a dual network architecture of a value function network and a policy network, wherein the value function network extracts features based on the business affinity matrix and the connection state matrix to obtain a state feature vector, and outputs a state value; the policy network extracts node association features based on the state feature vector, and outputs a node connection change action probability; Based on the state value and the reward value calculated based on the node processing capacity constraint, the link bandwidth constraint and the end-to-end delay constraint, a time difference error is calculated, the state feature vector, the node connection change action probability, the reward value and the state feature vector of the next state are stored in an experience pool as state transition information, a sampling priority is assigned to the state transition information in the experience pool based on the time difference error, training samples are obtained according to the sampling priority, and the parameters of the value function network are updated using the training samples; Constructing a policy objective function based on the action probability and state transition information of the node connection relationship change, calculating the policy gradient using the state value as a baseline function, and updating the parameters of the policy network using the policy gradient and state transition information under the policy trust region constraint; Using the temporal difference error as an advantage function, adjusting the improvement direction of the policy network based on the advantage function, generating a state access distribution using the node connection change action probability output by the policy network, and using the state access distribution for training the value function network; Monitor the changing trends of the reward value, the node connection change action probability output by the policy network, and the state value output by the value function network. When the fluctuation amplitude of the changing trend is less than the convergence threshold, extract the action sequence with the highest probability in the node connection change action probability output by the policy network as the optimal topological connection plan.

[0011] In an optional embodiment, Generate resource utilization indicators based on the target network topology, build a node operating environment and deploy network services through the resource optimization solution obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from the preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair based on the fault feature sequences, and generate large-scale network node scenarios that meet the constraints of the resource optimization solution, including: Construct a multidimensional resource state space, map the CPU state vector, memory state vector, network state vector and disk state vector of the network node in the target network topology structure to the multidimensional resource state space, use an adversarial variational autoencoder to perform adversarial training on the state vector to obtain a resource state distribution, calculate the resource state entropy based on the resource state distribution, construct a loss function of the resource prediction model, use the loss function to train a recurrent neural network to obtain a resource utilization prediction model, input the historical resource state distribution into the resource utilization prediction model to generate a future resource utilization index, and set resource allocation parameters based on the resource utilization index to generate a resource optimization plan; Calculating a system stability matrix based on the resource state entropy, performing singular value decomposition on the stability matrix to obtain a characteristic mode sequence, identifying a system state mutation point based on the characteristic mode sequence, taking the system state mutation point as a fault injection moment, and constructing a node operating environment and deploying network services at the fault injection moment according to the resource optimization solution; Performing stress testing on the network service to collect system status data, mapping the system status data to a characteristic manifold using a complex variable kernel function, calculating geodesics on the characteristic manifold to obtain a fault propagation path, constructing a fault feature sequence based on the curvature characteristics of the fault propagation path, performing manifold matching on the fault feature sequence and the vulnerability features in a preset vulnerability program library, and selecting a vulnerability program with the highest matching degree and satisfying the constraints of the resource optimization solution to be implanted into the node operating environment; The characteristic manifold is analyzed by a continuous coherence method to obtain the fault duration, a repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, anomaly detection and repair of the node operating environment are performed according to the repair threshold, and when the resource utilization index of the repaired node operating environment meets the constraints of the resource optimization solution, the current node operating environment is output as a large-scale network node scenario.

[0012] In an optional embodiment, The characteristic manifold is analyzed by the continuous coherence method to obtain the fault duration, and the repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, including: A nested sequence of simplex complexes is constructed on the feature manifold. The duration information of the fault feature is extracted using homology group mapping. The corrected fault duration is obtained by combining two-level feature weight optimization. The coupling matrix of fault duration and resource state entropy is established. The coupling matrix is ​​decomposed by features to obtain the repair threshold, which includes: Constructing a distance metric space on a characteristic manifold, calculating the distance value between point pairs based on the distance metric space, constructing a simplex complex using the distance value, generating a nested sequence of the simplex complex by gradually increasing the distance value, calculating the homology group mapping between adjacent simplex complexes in the nested sequence to obtain a topological characteristic sequence, extracting the appearance time and disappearance time of features in the topological characteristic sequence, calculating the feature duration based on the appearance time and disappearance time, and obtaining the fault duration by weighted summation of the feature duration; According to the structure of the simplex complex, a weight coefficient is assigned to the fault duration, the product of the weight coefficient and the fault duration is used as a dimensional eigenvalue, the dimensional eigenvalue is subjected to eigendecomposition to obtain a feature weight, and the product of the feature weight and the dimensional eigenvalue is summed to obtain a corrected fault duration; Calculate the correlation coefficient between the corrected fault duration and resource state entropy, fill the correlation coefficient into the diagonal matrix composed of the corrected fault duration and resource state entropy to obtain a coupling matrix, perform eigendecomposition on the coupling matrix to obtain eigenvectors, multiply the eigenvectors with the corrected fault duration and resource state entropy respectively and sum them to obtain a threshold judgment value, and use the threshold judgment value and the marked repair decision data to optimize to obtain a repair threshold.

[0013] According to a second aspect of the embodiments of the present invention, A large-scale network node scenario construction system based on a network range is provided, including: The first unit is used to calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; The second unit is used to calculate the node distribution density threshold using a graph clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain an initial network topology structure, generate a network node instance from a target network node template through attribute mapping, build a connection relationship between network node instances based on inter-node communication protocol information, extract communication features between network node instances and calculate service affinity, optimize the initial network topology structure based on service affinity, and generate a target network topology structure; The third unit is used to generate resource utilization indicators according to the target network topology, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate a fault feature sequence, select matching vulnerability programs from a preset vulnerability program library based on the fault feature sequence and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.

[0014] According to a third aspect of the embodiments of the present invention, An electronic device is provided, comprising: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the aforementioned method.

[0015] According to a fourth aspect of the embodiments of the present invention, A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.

[0016] In this embodiment, by constructing an attack and defense hierarchical node distribution diagram, the vulnerability association relationship between network nodes is accurately portrayed, and the simulation ability of the network range for complex network attack and defense environments is improved. By calculating the vulnerability chain propagation coefficient and optimizing the network topology structure in combination with the graph theory clustering algorithm, the rationality of the vulnerability propagation path can be effectively improved, making the exercise of network attack and defense strategies more realistic and targeted. The initial network topology structure is optimized by using the business affinity analysis method, so that the communication relationship between network nodes is more in line with the actual business scenario, and the accuracy of the simulation network is improved. At the same time, combined with the resource utilization prediction and optimization of the node operating environment, the dynamic construction of large-scale network nodes can be realized on the premise of ensuring the efficient use of computing resources in the network range, and the scalability and applicability of the network range can be improved. By generating a fault feature sequence through stress testing, and matching and implanting the vulnerability program based on the sequence, the impact of network attacks on service operation can be effectively simulated, and the accuracy of vulnerability reproduction can be improved. In addition, combined with the anomaly detection and repair mechanism, it can quickly respond to abnormal conditions in the network environment, improve the stability and security of network services, and thus build a more realistic and intelligent large-scale network range environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A schematic diagram of a flow chart of a method for constructing a large-scale network node scenario based on a network range according to an embodiment of the present invention; Figure 2 This is a comparison chart of the prediction accuracy of the vulnerability chain exploitation success rate according to an embodiment of the present invention; Figure 3 This is a comparison diagram of link load distribution before and after optimization of an embodiment of the present invention. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0019] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0020] Figure 1 FIG. 1 is a flow chart of a method for constructing a large-scale network node scenario based on a network range according to an embodiment of the present invention. Figure 1 As shown, the method includes: S101. Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; S102. Calculate the node distribution density threshold using a graph clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain an initial network topology structure, generate a network node instance from the target network node template through attribute mapping, build a connection relationship between network node instances based on the inter-node communication protocol information, extract the communication features between network node instances and calculate the service affinity, optimize the initial network topology structure based on the service affinity, and generate a target network topology structure; S103. Generate resource utilization indicators according to the target network topology structure, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from a preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequences, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.

[0021] In an optional implementation, the vulnerability correlation between nodes in the network node scenario construction requirements is calculated, the network nodes are divided into multiple attack and defense levels, a node distribution map of the attack and defense level is generated, a candidate network node template is extracted from a network node template library and a vulnerability chain propagation coefficient is calculated, the vulnerability chain propagation coefficient is matched with the attack and defense level node distribution map, and the target network node template is screened out, including: According to the vulnerability correlation between nodes, a node correlation graph is constructed. The node correlation graph is divided based on the community discovery algorithm to generate an attack and defense level node distribution graph. The vulnerability exploitation chain is introduced and the trigger probability of adjacent vulnerabilities and the attack chain length attenuation coefficient are calculated. The vulnerability intensity values ​​at the corresponding positions in the attack and defense level node distribution graph are matched. The candidate network node template with the minimum matching value is selected as the target network node template. Specifically, it includes: Obtain vulnerability attribute information of network nodes to generate node vulnerability feature vectors, calculate distance decay function values ​​based on the number of communication hops between nodes, perform tensor operations on the node vulnerability feature vectors and the distance decay function values ​​to obtain node vulnerability combination matrices, and calculate vulnerability correlations between nodes in network node scenario construction requirements based on the node vulnerability combination matrix; The vulnerability correlation degree is used as the edge weight to construct a node correlation graph, the node correlation graph is iteratively divided using a community discovery algorithm, the network nodes are divided into multiple attack and defense levels, and the level vulnerability strength value is calculated for each attack and defense level; Generate an attack and defense level node distribution graph based on the level position relationship of the attack and defense levels and the level vulnerability strength values, wherein the nodes represent the attack and defense levels, and the connecting edges between the nodes represent the vulnerability strength relationship between the levels; Extract candidate network node templates from a preset network node template library, establish connection relationships between vulnerabilities based on vulnerability features in the candidate network node templates through system state requirements, state changes, and attack entry types in the vulnerability features, introduce system state change continuity as a screening condition for vulnerability exploitation chains, and combine the cascade trigger probability of the attack chain with the length attenuation coefficient to calculate the vulnerability chain propagation coefficient; The vulnerability chain propagation coefficient is matched with the vulnerability strength value at the corresponding position in the attack and defense hierarchical node distribution map to obtain a propagation coefficient deviation value, and the hierarchical vulnerability strength change after deployment is calculated based on the candidate network node template. The weighted sum of the propagation coefficient deviation value and the hierarchical vulnerability strength change is determined as the matching value, and the candidate network node template with the minimum matching value is selected as the target network node template.

[0022] Exemplarily, the vulnerability attribute information of all network nodes in the scenario to be constructed is obtained, such as vulnerability type, CVE number, CVSS score, affected software version, etc. These vulnerability attribute information are converted into numerical feature vectors, such as using one-hot encoding to represent the vulnerability type, and using the numerical value of the CVSS score to represent the severity of the vulnerability. Assume that there are two nodes, the vulnerability feature vector of node A is [1, 0, 7.5], indicating that there is a type 1 vulnerability, no type 2 vulnerability, and the CVSS score is 7.5; the vulnerability feature vector of node B is [0, 1, 9.0], indicating that there is no type 1 vulnerability, a type 2 vulnerability, and a CVSS score of 9.0.

[0023] Calculate the distance attenuation function value between nodes. This function value is used to measure the impact of the communication distance between nodes on the vulnerability correlation. For example, a hop-based attenuation function can be used. The more hops there are, the greater the attenuation value. Assuming that the number of communication hops between node A and node B is 2, and the attenuation function is 1 / hop number, the attenuation value is 0.5.

[0024] The node vulnerability feature vector and the distance decay function value are operated to obtain the node vulnerability combination matrix, which reflects the strength of the vulnerability association between nodes.

[0025] For example, the element values ​​of the vulnerability combination matrix of node A and node B are [1×0.5, 0×0.5, 7.5×0.5, 0×0.5, 1×0.5, 9.0×0.5]=[0.5, 0, 3.75, 0, 0.5, 4.5].

[0026] The vulnerability correlation between nodes is calculated based on the node vulnerability combination matrix. For example, the element values ​​of the combination matrix can be weighted and summed to obtain a vulnerability correlation of 8.75 between nodes A and B.

[0027] The calculated vulnerability correlation degree is used as the edge weight to construct a node correlation graph. The nodes in the graph represent network nodes, the edges represent the vulnerability correlation relationship between nodes, and the edge weight represents the correlation strength.

[0028] The community discovery algorithm is used to iteratively divide the node association graph and divide the network nodes into multiple attack and defense levels. For example, the Louvain algorithm can be used for community discovery. Assume that the network nodes are divided into three levels, namely the core layer, the business layer, and the boundary layer.

[0029] Calculate the layer vulnerability strength value for each attack and defense layer. For example, the average CVSS score of all nodes in the layer can be used as the layer vulnerability strength value. Assume that the core layer vulnerability strength value is 8.0, the business layer vulnerability strength value is 7.0, and the boundary layer vulnerability strength value is 6.0.

[0030] The attack and defense layer node distribution diagram is generated based on the hierarchical position relationship and the layer vulnerability strength value of the attack and defense layer. The nodes in the diagram represent the attack and defense layers, and the lines between the nodes represent the vulnerability strength relationship between the layers. For example, the core layer is connected to the business layer, and the value on the line is 8.0 and 7.0, which is 1.0, indicating the potential threat level of the core layer to the business layer.

[0031] A candidate network node template is extracted from a preset network node template library. For example, the template library contains different types of node templates such as Web servers, database servers, and mail servers.

[0032] Based on the vulnerability features in the candidate network node template, the connection relationship between the vulnerabilities is established through the system state requirements, state changes, and attack entry types in the vulnerability features. For example, if the attack result of one vulnerability is the trigger condition of another vulnerability, then the two vulnerabilities can be connected to form an attack chain. The continuity of system state changes is introduced as a screening condition for vulnerability exploitation chains. For example, only vulnerabilities with continuous state changes can form a valid attack chain. The cascade trigger probability of the attack chain is combined with the length decay coefficient to calculate the vulnerability chain propagation coefficient. For example, an attack chain containing three vulnerabilities, the trigger probabilities of each vulnerability are 0.8, 0.9, and 0.7 respectively, and the length decay coefficient is 0.5, then the vulnerability chain propagation coefficient is 0.8×0.9×0.7×0.5=0.252.

[0033] The vulnerability chain propagation coefficient is matched with the vulnerability strength value of the corresponding position in the attack and defense hierarchical node distribution map to obtain the propagation coefficient deviation value. For example, the vulnerability chain propagation coefficient of the Web server template is compared with the boundary layer vulnerability strength value of 6.0 to obtain the deviation value. The change in the level vulnerability strength after deployment is calculated based on the candidate network node template. For example, after the Web server template is deployed, the boundary layer vulnerability strength value may change from 6.0 to 7.0, with a change of 1.0. The weighted sum of the propagation coefficient deviation value and the level vulnerability strength change is determined as the matching value. The candidate network node template with the minimum matching value is selected as the target network node template.

[0034] In this embodiment, by accurately calculating the vulnerability correlation between network nodes and constructing an attack and defense level node distribution map, the attack and defense structure of the network target range is made more realistic and hierarchical. The node correlation map is divided using the community discovery algorithm to ensure the rationality of the attack and defense levels, improve the accuracy of the attack path analysis, and by calculating the trigger probability and attenuation coefficient of the vulnerability exploitation chain, the propagation characteristics of the vulnerability in the network can be effectively characterized. By combining the node vulnerability feature vector and the distance attenuation function of the communication hop number, the vulnerability correlation is accurately measured, and the tensor calculation method is used to improve the calculation efficiency, making the network scene construction more efficient and intelligent. Introducing the continuity of system state changes as a screening condition for the vulnerability exploitation chain can more accurately evaluate the feasibility of the attack path and ensure that the selected network node template can truly reflect the dynamic process of vulnerability propagation. By matching the vulnerability chain propagation coefficient with the vulnerability intensity value of the attack and defense level, the optimal adaptation of the selected target network node template in terms of vulnerability propagation impact is ensured, thereby improving the simulation accuracy of the network target range. The weighted matching mechanism of the propagation coefficient deviation value and the change in the hierarchical vulnerability intensity can adaptively optimize the deployment strategy of network nodes and improve the rationality of vulnerability simulation, so that the finally generated network target range can more accurately reflect the attack chain propagation characteristics in the real network environment.

[0035] In an optional implementation, the connection relationship between vulnerabilities is established through the system state requirements, state changes and attack entry types in the vulnerability characteristics, the continuity of system state changes is introduced as the screening condition of the vulnerability exploitation chain, and the cascade trigger probability of the attack chain is combined with the length attenuation coefficient. The vulnerability chain propagation coefficient is calculated to include: Extract vulnerability features from the candidate network node template, wherein the vulnerability features include system state requirements triggered by the vulnerability, system state changes after the vulnerability is exploited, and attack entry types of the vulnerability exploitation, and construct a vulnerability feature vector; Perform feature matching according to the system state requirements, system state changes, and attack entry types in the vulnerability feature vector, and establish a connection relationship between the two vulnerabilities when the system state change of the first vulnerability meets the system state requirements of the second vulnerability and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability; Building a vulnerability dependency graph based on the connection relationship, identifying a vulnerability exploit chain path in the vulnerability dependency graph using a depth-first search method, screening the vulnerability exploit chain path according to the continuity of system state changes in the vulnerability feature vector, and generating a vulnerability exploit chain; Based on the number of nodes in the vulnerability exploit chain, the connection distance between adjacent nodes is calculated, the path length of the vulnerability exploit chain is calculated according to the connection distance, and the path length is substituted into an exponential decay function to obtain an attack chain length decay coefficient of the vulnerability exploit chain; For adjacent vulnerabilities in the vulnerability exploitation chain, the triggering probabilities of the adjacent vulnerabilities are multiplied in sequence according to the connection order of the vulnerabilities in the vulnerability exploitation chain to obtain the cascade triggering probability of the vulnerability exploitation chain, and the cascade triggering probability is multiplied by the attack chain length attenuation coefficient to obtain the vulnerability chain propagation coefficient; An attack path graph is constructed based on the vulnerability feature vector and the vulnerability exploitation chain, and the vulnerability exploitation chain is mapped to an attack path. The number of successes of the attack path is counted through multiple simulations, and the calculation parameters of the trigger probability and the attack chain length attenuation coefficient are optimized using the number of successes of the attack path. The vulnerability chain propagation coefficient is recalculated using the optimized parameters to obtain the final vulnerability chain propagation coefficient.

[0036] Exemplarily, vulnerability features are extracted from the candidate network node template to construct a vulnerability feature vector. Vulnerability features include the system state requirements triggered by the vulnerability, the system state changes after the vulnerability is exploited, and the attack entry type of the vulnerability exploit. For example, the feature vector of a vulnerability can be expressed as: the system state requirement is "Web service enabled", the system state change is "obtaining WebShell permissions", and the attack entry type is "remote code execution".

[0037] Perform feature matching based on vulnerability feature vectors to establish a connection relationship between vulnerabilities. When the system state change of the first vulnerability meets the system state requirements of the second vulnerability, and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability, a connection relationship is established between the two vulnerabilities. For example, the system state change of vulnerability A is "obtain WebShell permissions", the system state requirement of vulnerability B is "WebShell permissions", and the attack entry type of vulnerability B is "local command execution", and vulnerability A introduces the attack entry of "local command execution", then a connection relationship can be established between vulnerability A and vulnerability B.

[0038] A vulnerability dependency graph is constructed based on the connection relationship between vulnerabilities. The vulnerability dependency graph is a directed graph, where nodes represent vulnerabilities and edges represent the connection relationship between vulnerabilities. A depth-first search method is used to identify vulnerability exploit chain paths in the vulnerability dependency graph. For example, in the vulnerability dependency graph, if there is a path from vulnerability A to vulnerability B and then to vulnerability C, then this path is a vulnerability exploit chain path.

[0039] Filter the vulnerability exploit chain path according to the continuity of system state changes and generate the vulnerability exploit chain. The continuity of system state changes means that the system state changes of adjacent vulnerabilities in the vulnerability exploit chain must conform to a logical order. For example, if the system state change of vulnerability A is "obtaining WebShell permissions" and the system state change of vulnerability B is "escalating privileges to administrator permissions", then the system state changes of these two vulnerabilities are continuous. On the contrary, if the system state change of vulnerability A is "obtaining WebShell permissions" and the system state change of vulnerability B is "denial of service", then the system state changes of these two vulnerabilities are discontinuous, and this vulnerability exploit chain path needs to be filtered out.

[0040] Calculate the attack chain length decay coefficient of the vulnerability exploit chain. Based on the number of nodes in the vulnerability exploit chain, calculate the connection distance between adjacent nodes. The connection distance can be evaluated based on factors such as the difficulty of exploitation and the time required. For example, if the difficulty of exploitation between vulnerability A and vulnerability B is high, their connection distance is large. Calculate the path length of the vulnerability exploit chain based on the connection distance. The path length is the sum of all connection distances. Substitute the path length into the exponential decay function to get the attack chain length decay coefficient. The longer the path length, the smaller the decay coefficient. For example, the decay coefficient of a path length of 3 may be 0.8, and the decay coefficient of a path length of 5 may be 0.5.

[0041] Calculate the cascade trigger probability of the vulnerability exploit chain. For adjacent vulnerabilities in the vulnerability exploit chain, multiply the trigger probabilities of adjacent vulnerabilities in the order of connection of the vulnerabilities in the vulnerability exploit chain to obtain the cascade trigger probability of the vulnerability exploit chain. For example, the trigger probability of vulnerability A is 0.8, and the trigger probability of vulnerability B is 0.9, then the cascade trigger probability of the vulnerability exploit chain composed of vulnerability A and vulnerability B is 0.8×0.9=0.72.

[0042] Multiply the cascade trigger probability by the attack chain length attenuation coefficient to get the vulnerability chain propagation coefficient. For example, if the cascade trigger probability is 0.72 and the attack chain length attenuation coefficient is 0.8, then the vulnerability chain propagation coefficient is 0.72×0.8=0.576.

[0043] Based on the vulnerability feature vector and vulnerability exploit chain, an attack path diagram is constructed, and the vulnerability exploit chain is mapped to an attack path. The number of successful attack paths is counted through multiple simulations, and the calculation parameters of the trigger probability and the attack chain length attenuation coefficient are optimized using the number of successful attack paths. The vulnerability chain propagation coefficient is recalculated using the optimized parameters to obtain the final vulnerability chain propagation coefficient.

[0044] Figure 2This is a comparison chart of the prediction accuracy of the vulnerability chain utilization success rate of the embodiment of the present invention, which compares the difference between the vulnerability chain utilization success rate predicted by different methods and the actual observed value. The data shows that the average deviation between the predicted value of the technical solution and the actual observed value is only 4.2%, while the average deviations of the CVSS attack chain evaluation method, the multi-step attack graph analysis method and the traditional Bayesian network method are 12.8%, 9.6% and 15.3%, respectively. Especially in the medium complexity scenario, the predicted value of the technical solution is 68.5%, the actual observed value is 65.2%, and the deviation is only 3.3%; while the predicted values ​​of other methods are 55.6%, 76.4% and 48.9%, respectively, with significantly larger deviations. This shows that the technical solution significantly improves the prediction accuracy of the vulnerability chain utilization success rate through multiple simulation statistics and parameter optimization. It is worth noting that the CVSS method and the Bayesian network method usually underestimate the vulnerability chain utilization success rate, while the multi-step attack graph analysis law tends to overestimate, and these deviations may lead to the misallocation of security resources. This technical solution effectively overcomes these deviations by introducing the continuity of system state changes as a screening condition and combining multiple simulation statistics for parameter optimization, providing a more reliable decision-making basis for security defense.

[0045] In this embodiment, by matching the system state requirements, state changes and attack entry types, it is ensured that the construction of the vulnerability exploit chain conforms to the logic of the actual attack path, making the vulnerability propagation path more accurate. The vulnerability exploit chain is identified in the vulnerability dependency graph using the depth-first search method, and the continuity of system state changes is introduced as a screening condition to effectively eliminate unreasonable attack paths and improve the reliability of vulnerability propagation analysis. By calculating the length attenuation coefficient of the attack chain and combining the multiplication operation of the vulnerability trigger probability, the vulnerability chain propagation capability is accurately evaluated to avoid the misjudgment caused by ignoring the attenuation effect of the attack path in the traditional method. In addition, the number of successful attack paths is calculated by multiple simulations, and the calculation parameters of the trigger probability and the attenuation coefficient are optimized to make the vulnerability propagation model closer to the real network attack environment and improve the accuracy of vulnerability propagation risk assessment. It can effectively screen out the most valuable vulnerability exploit chains, optimize the vulnerability propagation path analysis, improve the scientific nature of network security assessment and defense strategy formulation, provide more realistic attack chain simulations for attack and defense drills in the network target range, and improve the pertinence and practicality of security research and defense systems.

[0046] In an optional implementation, a graph clustering algorithm is used to calculate the node distribution density threshold and the network topology type in the network node scenario construction requirement is hierarchically optimized to obtain an initial network topology structure, a target network node template is generated into a network node instance through attribute mapping, a connection relationship between network node instances is constructed based on the communication protocol information between nodes, communication features between network node instances are extracted and business affinity is calculated, the initial network topology structure is optimized based on the business affinity, and generating a target network topology structure includes: A distance matrix is ​​constructed according to the Euclidean distance between nodes. A graph clustering algorithm is used based on the distance matrix to calculate the local density and relative density of nodes. A density threshold is set in combination with the network node scenario construction requirements. The local density and relative density of the nodes are normalized to obtain the node comprehensive density value. The nodes are hierarchically divided according to the network topology layering requirements. The topological connection relationship of the nodes in each layer is determined according to the comprehensive density value. The initial network topology structure that meets the hierarchical constraints is obtained through iterative optimization. Extracting hardware configuration information and software configuration information from the target network node template, constructing a static attribute feature set and a dynamic attribute feature set, mapping the static attribute feature set to the hardware parameters of the node instance based on the feature mapping rule, mapping the dynamic attribute feature set to the software parameters of the node instance, and generating a network node instance; Design a protocol feature tensor, encode the communication protocol information between node instances into a multi-dimensional feature tensor, use a tensor decomposition method to extract implicit factors of the protocol features, build a protocol similarity measurement model based on the implicit factors, calculate the protocol compatibility matrix between node instances, and determine the connection relationship between node instances according to the compatibility threshold; A sliding time window is used to extract the business traffic time series characteristics between network node instances. The business traffic time series characteristics are analyzed based on the long short-term memory network to obtain the business traffic prediction results. A business dependency graph is constructed through service call chain analysis. The node association characteristics in the business dependency graph are extracted in combination with the graph attention network. The node resource utilization characteristics are counted based on resource monitoring data. The business traffic prediction results, node association characteristics and resource utilization characteristics are fused in multiple dimensions to calculate the business affinity. Taking business affinity as the state space and the change of connection relationship between network node instances as the action space, a reward function that considers node processing capacity constraints, link bandwidth constraints and end-to-end delay constraints is constructed. The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topology connection plan is output. The initial network topology structure is optimized through the optimal topology connection plan to generate the target network topology structure.

[0047] Exemplarily, the node distribution density is calculated and the initial topology is constructed first. The distance matrix is ​​constructed by calculating the Euclidean distance between each node in the network, and the distance value is calculated by the physical position coordinates of the node. Taking a network containing 100 nodes as an example, each node has a three-dimensional coordinate value, and the distance between them is calculated by traversing all node pairs. For each node, the number of nodes within its neighborhood is counted as the local density value, and the minimum distance to other high-density nodes is calculated as the relative density value. For example, if the neighborhood radius is set to 10 unit distances, the local density of a node is 15, which means that there are 15 adjacent nodes within the range.

[0048] Then extract the node template information and generate an instance. The node template contains hardware parameters such as the number of CPU cores, memory capacity, storage space, and software parameters such as the operating system type and operating environment configuration. For example, a computing node template may contain a hardware configuration of a 16-core CPU, 64GB of memory, and 512GB of storage space, as well as software configurations of the Linux operating system and Docker container environment. These parameters are instantiated through feature mapping rules to generate specific node instances.

[0049] Then analyze the communication protocol features between nodes. Encode TCP / IP, HTTP and other protocol information into feature vectors, including protocol type, port number, message format and other dimensions. Extract the main features through feature decomposition and calculate the protocol compatibility between nodes. For example, if two nodes support HTTP protocol and the port configurations match, their protocol compatibility is high.

[0050] Optimize the topology based on business traffic characteristics. Use a 5-minute sliding time window to count the business traffic between nodes, and combine historical data to predict future traffic trends. At the same time, analyze the service call relationship and build a dependency graph. For example, there are an average of 1,000 requests per second between nodes A and B, and there is a direct service call dependency, which means that their business affinity is high.

[0051] Finally, the connection relationship is optimized through deep reinforcement learning. The state space is defined to contain the business affinity matrix of the nodes, and the action space contains the operations of adding or deleting connections between nodes. The reward function is set to consider constraints such as processing power, bandwidth, and latency. The optimal connection strategy is obtained through iterative training to generate the final network topology.

[0052] In this embodiment, through graph clustering and multi-level optimization, the automatic construction of network topology is realized, and the efficiency and accuracy of network planning are improved. The hierarchical method based on node density analysis makes the network structure more reasonable and avoids the problem of uneven node distribution. The feasibility of connection between node instances is guaranteed by feature mapping and protocol compatibility analysis, and the interoperability and reliability of the network are improved. The dynamic attribute mapping mechanism enables the network to have better scalability and adaptability. The optimization method based on business affinity and deep reinforcement learning realizes the dynamic adjustment of network topology and improves network performance and resource utilization. Through multi-dimensional feature fusion and constraint consideration, the practicality and feasibility of the optimization results are ensured.

[0053] In an optional implementation, a deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm, and when the reward function converges, the optimal topological connection solution is output, including: A dual network architecture of value function network and policy network is constructed. The temporal difference error is used to guide the priority sampling of the experience pool and the parameters are optimized based on the policy trust region constraint. At the same time, the advantage function is used to adjust the improvement direction of the policy network and the state access distribution is introduced to guide the training of the value function network. When the optimization converges, the sequence with the highest action probability is output as the optimal topological connection solution, which includes: Obtaining the business affinity matrix and the connection state matrix of the initial network topology structure, and constructing a dual network architecture of a value function network and a policy network, wherein the value function network extracts features based on the business affinity matrix and the connection state matrix to obtain a state feature vector, and outputs a state value; the policy network extracts node association features based on the state feature vector, and outputs a node connection change action probability; Based on the state value and the reward value calculated based on the node processing capacity constraint, the link bandwidth constraint and the end-to-end delay constraint, a time difference error is calculated, the state feature vector, the node connection change action probability, the reward value and the state feature vector of the next state are stored in an experience pool as state transition information, a sampling priority is assigned to the state transition information in the experience pool based on the time difference error, training samples are obtained according to the sampling priority, and the parameters of the value function network are updated using the training samples; Constructing a policy objective function based on the action probability and state transition information of the node connection relationship change, calculating the policy gradient using the state value as a baseline function, and updating the parameters of the policy network using the policy gradient and state transition information under the policy trust region constraint; Using the temporal difference error as an advantage function, adjusting the improvement direction of the policy network based on the advantage function, generating a state access distribution using the node connection change action probability output by the policy network, and using the state access distribution for training the value function network; Monitor the changing trends of the reward value, the node connection change action probability output by the policy network, and the state value output by the value function network. When the fluctuation amplitude of the changing trend is less than the convergence threshold, extract the action sequence with the highest probability in the node connection change action probability output by the policy network as the optimal topological connection plan.

[0054] Exemplarily, a dual network architecture system is first constructed. The value function network adopts a three-layer fully connected neural network structure. The input layer receives the business affinity matrix and the connection state matrix, and extracts features through convolution operations to obtain the state feature vector. Taking a network containing 5 nodes as an example, the business affinity matrix is ​​a 5x5 symmetric matrix. In the connection state matrix, 1 indicates that there is a connection between the nodes, and 0 indicates that there is no connection. The hidden layer contains 128 neurons, using the ReLU activation function, and the output layer outputs a scalar state value. The policy network also adopts a three-layer structure, with a shared state feature vector as input, and extracts the correlation features between nodes through the graph attention layer. The output layer uses the Softmax function to obtain the probability of node connection change action.

[0055] Then, experience replay training is performed. The reward value calculated based on the current state value and the constraints such as node CPU utilization less than 80%, link bandwidth utilization less than 60%, and end-to-end delay less than 100ms is used to calculate the time difference error. The transfer information consisting of the state feature vector, action probability, reward value, and next state feature vector is stored in an experience pool with a capacity of 10,000. Sampling weights are assigned to the samples in the experience pool according to the size of the time difference error. The larger the time difference error, the higher the weight. Each training is performed by sampling 256 samples from the experience pool according to the weight to update the network parameters of the value function.

[0056] Then optimize the policy network. Construct a policy objective function based on action probability and state transition information, and use the state value as the baseline function to calculate the policy improvement direction. Under the constraint that the Kullback-Leibler divergence (KL divergence) between the new and old policies is less than 0.01, use the Adam optimizer with a learning rate of 0.001 to update the policy network parameters. At the same time, use the time difference error as the advantage function to adjust the policy network improvement direction, and the action probability output by the policy network is used to generate the state access distribution to guide the value function network training.

[0057] Finally, the convergence is judged. For every 1000 training steps, the average reward value, action probability, and change rate of the state value in the last 100 steps are calculated. When the change rate of the three is less than 1%, convergence is determined, and the action sequence with the highest probability of output by the policy network is extracted as the optimal solution.

[0058] Figure 3This is a comparison diagram of link load distribution before and after optimization of the embodiment of the present invention, which shows the comparison of link load distribution before and after network topology optimization. It can be clearly seen from the distribution curve that the link load distribution before optimization (dashed line) presents a "U-shaped" distribution with high ends and low middle, indicating that there are a large number of low-load and high-load links in the network at the same time, and resource utilization is unbalanced. Specific data show that before optimization, about 15% of the link load rates are lower than 20% (in an idle state), and about 12% of the link load rates exceed 80% (in a congested state), of which 5% of the link load rates even exceed 95%. After optimization by this technical solution (solid line), the link load distribution presents a more concentrated "bell-shaped" distribution, which is overall concentrated in the middle load range (40%-70%). After optimization, the proportion of low-load links (<20%) is reduced to 8%, the proportion of high-load links (>80%) is reduced to 7%, and no link load rate exceeds 90%. Especially in the ideal load range of 40%-60%, the number of optimized links increased from 17 to 24, accounting for 48% of the total number of links. This significant improvement in load balancing directly reflects that this technical solution can effectively identify congestion points and idle resources in the network, and achieve a more reasonable allocation of network resources by intelligently adjusting the topological connection structure, thereby improving the overall network performance and user experience.

[0059] In this embodiment, by constructing a dual network architecture of a value function network and a policy network, an end-to-end solution to the complex network topology optimization problem is achieved, avoiding the limitation of the traditional heuristic algorithm that requires manual design of optimization rules. A training method combining priority experience replay based on temporal difference error and policy trust region constraints is adopted to improve the sample utilization efficiency and ensure stable policy improvement, thereby accelerating the algorithm convergence speed. The introduction of a two-way guidance mechanism of advantage function and state access distribution realizes the coordinated optimization of value function estimation and policy improvement, improves the algorithm performance and ensures the reliability of the output topology solution.

[0060] In an optional implementation, a resource utilization index is generated according to a target network topology structure, a node operating environment is constructed and a network service is deployed by using a resource optimization scheme obtained by predicting the resource utilization index, a stress test is performed on the network service to generate a fault feature sequence, a matching vulnerability program is selected from a preset vulnerability program library based on the fault feature sequence and implanted into the node operating environment, status information in the node operating environment is monitored, and anomaly detection and repair are performed according to the fault feature sequence, and a large-scale network node scenario that meets the constraints of the resource optimization scheme is generated, including: Construct a multidimensional resource state space, map the CPU state vector, memory state vector, network state vector and disk state vector of the network node in the target network topology structure to the multidimensional resource state space, use an adversarial variational autoencoder to perform adversarial training on the state vector to obtain a resource state distribution, calculate the resource state entropy based on the resource state distribution, construct a loss function of the resource prediction model, use the loss function to train a recurrent neural network to obtain a resource utilization prediction model, input the historical resource state distribution into the resource utilization prediction model to generate a future resource utilization index, and set resource allocation parameters based on the resource utilization index to generate a resource optimization plan; Calculating a system stability matrix based on the resource state entropy, performing singular value decomposition on the stability matrix to obtain a characteristic mode sequence, identifying a system state mutation point based on the characteristic mode sequence, taking the system state mutation point as a fault injection moment, and constructing a node operating environment and deploying network services at the fault injection moment according to the resource optimization solution; Performing stress testing on the network service to collect system status data, mapping the system status data to a characteristic manifold using a complex variable kernel function, calculating geodesics on the characteristic manifold to obtain a fault propagation path, constructing a fault feature sequence based on the curvature characteristics of the fault propagation path, performing manifold matching on the fault feature sequence and the vulnerability features in a preset vulnerability program library, and selecting a vulnerability program with the highest matching degree and satisfying the constraints of the resource optimization solution to be implanted into the node operating environment; The characteristic manifold is analyzed by a continuous coherence method to obtain the fault duration, a repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, anomaly detection and repair of the node operating environment are performed according to the repair threshold, and when the resource utilization index of the repaired node operating environment meets the constraints of the resource optimization solution, the current node operating environment is output as a large-scale network node scenario.

[0061] A method for building large-scale network node scenarios that can simulate real network environments for testing and verifying the stability and reliability of network services. The core of this method is to optimize resource allocation based on the target network topology and resource utilization prediction results, and simulate failures and repairs on nodes.

[0062] Exemplarily, first, the target network topology information is collected, including the number of nodes, connection relationships, and the hardware configuration of each node, such as the number of CPU cores, memory size, network bandwidth, and disk capacity, etc. Then, the state information such as CPU usage, memory usage, network traffic, and disk IO of the network nodes is collected, and this information is converted into a multi-dimensional vector representation, such as a CPU state vector, a memory state vector, a network state vector, and a disk state vector.

[0063] Next, we train these state vectors using an adversarial variational autoencoder. The adversarial variational autoencoder consists of two parts: an encoder and a decoder. The encoder compresses the high-dimensional state vector into a low-dimensional representation, while the decoder attempts to reconstruct the original state vector from the low-dimensional representation. Through adversarial training, the encoder can extract key features from the state vector and learn the probability distribution of resource states.

[0064] Based on the learned resource state distribution, the resource state entropy is calculated. The entropy value reflects the degree of disorder of the resource state. The higher the entropy value, the more unstable the resource state. The resource state entropy is used to construct the loss function of the resource prediction model, and the loss function is used to train the recurrent neural network, such as the long short-term memory network (LSTM), to predict the resource utilization in the future. By inputting the historical resource state distribution into the trained recurrent neural network, future resource utilization indicators can be obtained, such as the CPU usage and memory usage of each node in the future.

[0065] According to the predicted resource utilization indicators, a resource optimization plan is formulated, such as determining the CPU allocation quota and memory allocation quota of each node. Then, the system stability matrix is ​​calculated based on the resource state entropy, which reflects the stability of the system under different resource states. The stability matrix is ​​subjected to singular value decomposition to obtain the characteristic mode sequence, which reflects the change trend of the system state over time. By analyzing the characteristic mode sequence, the system state mutation points are identified, that is, the moments when the system stability changes significantly. These mutation points are used as fault injection moments.

[0066] At the preset fault injection moment, the node operating environment is built according to the resource optimization plan, and the network service is deployed on the node. Then, the deployed network service is stress tested, such as simulating a large number of users accessing the service at the same time, and collecting system status data, such as CPU usage, memory usage, network latency, etc. The collected system status data is mapped to a high-dimensional feature manifold using a complex variable kernel function, and the geodesic is calculated on the manifold to obtain the fault propagation path. The curvature feature is calculated based on the fault propagation path, and a fault feature sequence is constructed, which describes the feature changes during the fault propagation process.

[0067] The generated fault feature sequence is matched with the vulnerability features in the preset vulnerability program library, and the vulnerability program with the highest matching degree and meeting the resource optimization plan constraints is selected and implanted into the node running environment. The preset vulnerability program library contains various types of vulnerability programs, such as buffer overflow vulnerabilities, SQL injection vulnerabilities, etc. Each vulnerability program has a corresponding feature description.

[0068] The characteristic manifold is analyzed by the continuous homology method to obtain the fault duration, which reflects the length of time the fault lasts. The repair threshold is constructed based on the coupling relationship between resource state entropy and fault duration. When the system state entropy and fault duration exceed the repair threshold, it is considered that the system needs to be repaired. According to the repair threshold, the node operating environment is detected and repaired for anomalies, such as restarting services, updating patches, etc. When the resource utilization index of the repaired node operating environment meets the constraints of the resource optimization solution, the current node operating environment is output as a large-scale network node scenario.

[0069] For example, in a network with 10 nodes, a resource state vector was constructed by collecting the CPU usage and memory usage of the nodes. After training the adversarial variational autoencoder, the resource state distribution was obtained. The resource state entropy was calculated using the distribution, and the recurrent neural network was trained to predict the resource utilization in the next 24 hours. According to the prediction results, the CPU allocation quota of each node was set to 80% and the memory allocation quota was set to 70%. When simulating fault injection, the buffer overflow vulnerability program was selected and implanted into node 3. After anomaly detection and repair, the CPU usage and memory usage of node 3 returned to normal levels, meeting the constraints of the resource optimization solution.

[0070] In this embodiment, by constructing a multi-dimensional resource state space, the CPU, memory, network and disk resource states of the network nodes are accurately depicted, and the adversarial variational autoencoder is used for training to make the resource state distribution more realistic and improve the accuracy of resource utilization prediction. Based on the prediction model, the future resource utilization index is generated, and the resource allocation plan is optimized, thereby improving the overall resource management efficiency of the system. By calculating the resource state entropy and combining the singular value decomposition method, the system state mutation point can be effectively identified, the fault injection time can be accurately determined, and the fault simulation can be made more realistic. The system state data is mapped to the characteristic manifold using the complex variable kernel function, and the geodesic line is calculated to analyze the fault propagation path, so that the fault feature extraction is more accurate. Combined with the fault feature manifold matching method, the vulnerability program that best meets the resource optimization constraints can be screened in the preset vulnerability program library, thereby improving the pertinence and effectiveness of the vulnerability test. The continuous coherence analysis method is used to calculate the fault duration, and the repair threshold is constructed in combination with the resource state entropy to realize the intelligent anomaly detection and repair of the node operation environment, ensuring that the repaired environment can meet the constraints of the resource optimization plan. Ultimately, this solution can build large-scale network node scenarios that meet resource optimization requirements, improve the authenticity, stability, and efficiency of network simulation and attack and defense testing, and provide strong support for network security research and infrastructure optimization.

[0071] In an optional implementation, the characteristic manifold is analyzed by a continuous coherence method to obtain the fault duration, and the repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, including: A nested sequence of simplex complexes is constructed on the feature manifold. The duration information of the fault feature is extracted using homology group mapping. The corrected fault duration is obtained by combining two-level feature weight optimization. The coupling matrix of fault duration and resource state entropy is established. The coupling matrix is ​​decomposed by features to obtain the repair threshold, which includes: Constructing a distance metric space on a characteristic manifold, calculating the distance value between point pairs based on the distance metric space, constructing a simplex complex using the distance value, generating a nested sequence of the simplex complex by gradually increasing the distance value, calculating the homology group mapping between adjacent simplex complexes in the nested sequence to obtain a topological characteristic sequence, extracting the appearance time and disappearance time of features in the topological characteristic sequence, calculating the feature duration based on the appearance time and disappearance time, and obtaining the fault duration by weighted summation of the feature duration; According to the structure of the simplex complex, a weight coefficient is assigned to the fault duration, the product of the weight coefficient and the fault duration is used as a dimensional eigenvalue, the dimensional eigenvalue is subjected to eigendecomposition to obtain a feature weight, and the product of the feature weight and the dimensional eigenvalue is summed to obtain a corrected fault duration; Calculate the correlation coefficient between the corrected fault duration and resource state entropy, fill the correlation coefficient into the diagonal matrix composed of the corrected fault duration and resource state entropy to obtain a coupling matrix, perform eigendecomposition on the coupling matrix to obtain eigenvectors, multiply the eigenvectors with the corrected fault duration and resource state entropy respectively and sum them to obtain a threshold judgment value, and use the threshold judgment value and the marked repair decision data to optimize to obtain a repair threshold.

[0072] Exemplarily, first, a nested sequence of simplex complexes is constructed on the characteristic manifold. The characteristic manifold is a topological representation of the system state. It is a geometric structure of a high-dimensional space, and each point represents the resource state of the system at a certain moment, including CPU load, memory usage, network bandwidth usage, and disk IO status. The manifold can capture the continuous changes in the system state and is suitable for analyzing fault propagation modes. The simplex complex is a topological structure composed of multiple simplices (such as points, line segments, triangles and their high-dimensional generalizations) to represent the topological connection relationship between data points. To construct a simplex complex on a manifold, it is first necessary to define a distance metric space for calculating the similarity between data points. The distance metric space can be calculated by using methods such as Euclidean distance, Mahalanobis distance or cosine similarity to measure the differences between different resource state vectors.

[0073] After constructing the distance metric space, it is necessary to calculate the distance value between the point pairs. This distance value is used to judge the similarity between two data points (i.e., resource status). When the distance is less than the set threshold, a topological connection is established between them to form a simplex. As the distance threshold gradually increases, the structure of the simplex complex will gradually change, thus forming a nested sequence, that is, a topological structure at different scales. The construction of nested sequences can be achieved through methods such as Vietoris-Rips Complex (VR Complex), which can gradually connect data points at different scales to generate hierarchical changes in topological structures.

[0074] After constructing the nested sequence, it is necessary to use homology group mapping to analyze the changes in topological features at different scales. Homology group is a topological invariant that can characterize features such as connected components, ring structures, and holes in the topological structure of data. For example, at a small scale, different resource states may be independent of each other, but as the scale increases, some states will gradually merge, and this change can be reflected by homology group mapping. Homology group mapping is used to analyze the changes in topological features between adjacent simplex complexes and generate a topological feature sequence, which includes the appearance and disappearance times of each topological feature.

[0075] Based on the appearance and disappearance times, the feature duration can be calculated, that is, the existence time of a topological feature at different scales. Features with longer durations usually indicate stable topological structures, such as some long-standing resource status patterns of the system; while features with shorter durations may indicate transient anomalies, such as sudden CPU load surges or network congestion. Therefore, by calculating the duration of topological features and performing a weighted summation, we can obtain a preliminary fault duration, which is used to measure the stability and impact range of system faults.

[0076] In order to optimize the fault duration, it is necessary to combine the structural characteristics of the simplex complex for weighted processing. The structural characteristics of the simplex complex include topological connectivity, local density, dimensional information, etc. By calculating the local connectivity of each simplex, its importance in the entire topological structure is determined, and a weighting coefficient is assigned to it. By multiplying these weighting coefficients with the fault duration value, the dimensional eigenvalues ​​of each dimension can be obtained. Then, these dimensional eigenvalues ​​are feature decomposed, and the feature weights of different dimensions are calculated. Finally, the corrected fault duration is obtained, which improves the accuracy and robustness of fault analysis.

[0077] Next, the coupling relationship between the corrected fault duration and resource state entropy is calculated, and then the coupling matrix is ​​constructed. Resource state entropy is used to measure the balance of system resources. It is based on the concept of information entropy and evaluates the stability of the system by calculating the distribution of resource states such as CPU, memory, network, and disk. A higher entropy value indicates that resource usage is more uniform and the system is more stable, while a lower entropy value indicates that some resources are abnormal, such as excessive CPU usage or a bottleneck on a network port.

[0078] In order to establish the relationship between fault persistence and resource state entropy, we first need to calculate their correlation coefficient to measure the coupling degree between the two variables. Then, the correlation coefficient is filled into the diagonal matrix composed of the modified fault persistence and resource state entropy to generate the coupling matrix. The coupling matrix is ​​used to describe the global correlation between the system resource state and fault persistence.

[0079] After the coupling matrix is ​​constructed, eigendecomposition is required to extract key eigenvectors. These eigenvectors are used to identify the main factors affecting system stability, such as certain resource status patterns that may cause specific types of failures. Based on the eigenvectors, the threshold judgment value can be calculated to measure whether the system is in an acceptable operating state. The specific calculation method is to multiply the eigenvector with the corrected fault duration and resource status entropy respectively and sum them to obtain a global threshold indicator.

[0080] In order to optimize the threshold determination results, it is necessary to use historical repair decision data for adjustment. Historical repair decision data includes information such as system failures that occurred in the past, the scope of failure impact, the repair measures taken and their effectiveness. Through machine learning methods, such as methods based on gradient boosting decision trees or Bayesian optimization, the parameters of the threshold calculation model can be adjusted to make it more consistent with the actual system operation. The optimized repair threshold can more accurately judge the system's fault recovery capabilities under different resource states and is used to guide the execution of automated repair strategies.

[0081] Table 1 is a comprehensive performance index comparison table of different fault analysis methods in the embodiments of the present invention, which comprehensively compares the performance of the present technical solution with other methods in multiple performance indicators. The present technical solution achieves 94.6% in fault detection accuracy, which is significantly higher than other methods, while maintaining the lowest false alarm rate (3.2%) and missed alarm rate (2.2%). In terms of processing time, although the traditional statistical method is faster (0.57ms / sample), the present technical solution (0.98ms / sample) has obvious advantages over the deep learning method (2.86ms / sample) and the classical coherence analysis (1.74ms / sample). In terms of resource consumption, the present technical solution (245MB) is much lower than the deep learning method (876MB), saving about 40% of resources compared with the classical coherence analysis (412MB).

[0082] Table 1. Comparison of comprehensive performance indicators of different fault analysis methods;

[0083] In this embodiment, by constructing characteristic manifolds and using simplex complexes to analyze the system state, the topological relationship between different resource states can be accurately captured, thereby improving the accuracy of fault detection. The homology group mapping is used to analyze the changes in topological characteristics, so that the fault duration calculation can reflect the fault impact range of the system at different scales, thereby improving the anomaly detection capability. By calculating the entropy of the resource state and coupling it with the fault duration for analysis, the overall stability of the system can be better measured, thereby achieving refined resource management and fault prediction. The repair threshold is optimized through characteristic decomposition, and dynamically adjusted in combination with historical repair decision data, so that the repair threshold is more in line with the actual application scenario, thereby improving the effectiveness and adaptability of the automated repair strategy.

[0084] According to a second aspect of the embodiments of the present invention, A large-scale network node scenario construction system based on a network range is provided, the system comprising: The first unit is used to calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; The second unit is used to calculate the node distribution density threshold using a graph clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain an initial network topology structure, generate a network node instance from a target network node template through attribute mapping, build a connection relationship between network node instances based on inter-node communication protocol information, extract communication features between network node instances and calculate service affinity, optimize the initial network topology structure based on service affinity, and generate a target network topology structure; The third unit is used to generate resource utilization indicators according to the target network topology, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate a fault feature sequence, select matching vulnerability programs from a preset vulnerability program library based on the fault feature sequence and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.

[0085] According to a third aspect of the embodiments of the present invention, An electronic device is provided, comprising: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the aforementioned method.

[0086] According to a fourth aspect of the embodiments of the present invention, A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.

[0087] The present invention may be a method, an apparatus, a system and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for executing various aspects of the present invention.

[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A large-scale network node scenario construction method based on a network range, characterized in that: include: Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; A graph clustering algorithm is used to calculate the node distribution density threshold and hierarchically optimize the network topology type in the network node scenario construction requirements to obtain the initial network topology structure. The target network node template is used to generate a network node instance through attribute mapping. The connection relationship between network node instances is constructed based on the communication protocol information between nodes. The communication characteristics between network node instances are extracted and the business affinity is calculated. The initial network topology structure is optimized based on the business affinity to generate the target network topology structure. Generate resource utilization indicators according to the target network topology structure, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from the preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment, and perform anomaly detection and repair according to the fault feature sequences, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.

2. The method according to claim 1, characterized in that Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node templates including: According to the vulnerability correlation between nodes, a node correlation graph is constructed. The node correlation graph is divided based on the community discovery algorithm to generate an attack and defense level node distribution graph. The vulnerability exploitation chain is introduced and the trigger probability of adjacent vulnerabilities and the attack chain length attenuation coefficient are calculated. The vulnerability intensity values ​​at the corresponding positions in the attack and defense level node distribution graph are matched. The candidate network node template with the minimum matching value is selected as the target network node template. Specifically, it includes: Obtain vulnerability attribute information of network nodes to generate node vulnerability feature vectors, calculate distance decay function values ​​based on the number of communication hops between nodes, perform tensor operations on the node vulnerability feature vectors and the distance decay function values ​​to obtain node vulnerability combination matrices, and calculate vulnerability correlations between nodes in network node scenario construction requirements based on the node vulnerability combination matrix; The vulnerability correlation degree is used as the edge weight to construct a node correlation graph, the node correlation graph is iteratively divided using a community discovery algorithm, the network nodes are divided into multiple attack and defense levels, and the level vulnerability strength value is calculated for each attack and defense level; Generate an attack and defense level node distribution graph based on the level position relationship of the attack and defense levels and the level vulnerability strength values, wherein the nodes represent the attack and defense levels, and the connecting edges between the nodes represent the vulnerability strength relationship between the levels; Extract candidate network node templates from a preset network node template library, establish connection relationships between vulnerabilities based on vulnerability features in the candidate network node templates through system state requirements, state changes, and attack entry types in the vulnerability features, introduce system state change continuity as a screening condition for vulnerability exploitation chains, and combine the cascade trigger probability of the attack chain with the length attenuation coefficient to calculate the vulnerability chain propagation coefficient; The vulnerability chain propagation coefficient is matched with the vulnerability strength value at the corresponding position in the attack and defense hierarchical node distribution map to obtain a propagation coefficient deviation value, and the hierarchical vulnerability strength change after deployment is calculated based on the candidate network node template. The weighted sum of the propagation coefficient deviation value and the hierarchical vulnerability strength change is determined as the matching value, and the candidate network node template with the minimum matching value is selected as the target network node template.

3. The method according to claim 2, characterized in that The connection relationship between vulnerabilities is established through the system state requirements, state changes and attack entry types in the vulnerability characteristics. The continuity of system state changes is introduced as the screening condition for the vulnerability exploit chain. The cascade trigger probability of the attack chain is combined with the length attenuation coefficient. The vulnerability chain propagation coefficient is calculated, including: Extract vulnerability features from the candidate network node template, wherein the vulnerability features include system state requirements triggered by the vulnerability, system state changes after the vulnerability is exploited, and attack entry types of the vulnerability exploitation, and construct a vulnerability feature vector; Perform feature matching according to the system state requirements, system state changes, and attack entry types in the vulnerability feature vector, and establish a connection relationship between the two vulnerabilities when the system state change of the first vulnerability meets the system state requirements of the second vulnerability and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability; Building a vulnerability dependency graph based on the connection relationship, identifying a vulnerability exploit chain path in the vulnerability dependency graph using a depth-first search method, screening the vulnerability exploit chain path according to the continuity of system state changes in the vulnerability feature vector, and generating a vulnerability exploit chain; Based on the number of nodes in the vulnerability exploit chain, the connection distance between adjacent nodes is calculated, the path length of the vulnerability exploit chain is calculated according to the connection distance, and the path length is substituted into an exponential decay function to obtain an attack chain length decay coefficient of the vulnerability exploit chain; For adjacent vulnerabilities in the vulnerability exploitation chain, the triggering probabilities of the adjacent vulnerabilities are multiplied in sequence according to the connection order of the vulnerabilities in the vulnerability exploitation chain to obtain the cascade triggering probability of the vulnerability exploitation chain, and the cascade triggering probability is multiplied by the attack chain length attenuation coefficient to obtain the vulnerability chain propagation coefficient; An attack path graph is constructed based on the vulnerability feature vector and the vulnerability exploitation chain, and the vulnerability exploitation chain is mapped to an attack path. The number of successes of the attack path is counted through multiple simulations, and the calculation parameters of the trigger probability and the attack chain length attenuation coefficient are optimized using the number of successes of the attack path. The vulnerability chain propagation coefficient is recalculated using the optimized parameters to obtain the final vulnerability chain propagation coefficient.

4. The method according to claim 1, characterized in that The graph clustering algorithm is used to calculate the node distribution density threshold and the network topology type in the network node scenario construction requirements is hierarchically optimized to obtain the initial network topology structure. The target network node template is used to generate a network node instance through attribute mapping. The connection relationship between network node instances is constructed based on the communication protocol information between nodes. The communication characteristics between network node instances are extracted and the business affinity is calculated. The initial network topology structure is optimized based on the business affinity. The target network topology structure is generated, including: A distance matrix is ​​constructed according to the Euclidean distance between nodes. A graph clustering algorithm is used based on the distance matrix to calculate the local density and relative density of nodes. A density threshold is set in combination with the network node scenario construction requirements. The local density and relative density of the nodes are normalized to obtain the node comprehensive density value. The nodes are hierarchically divided according to the network topology layering requirements. The topological connection relationship of the nodes in each layer is determined according to the comprehensive density value. The initial network topology structure that meets the hierarchical constraints is obtained through iterative optimization. Extracting hardware configuration information and software configuration information from the target network node template, constructing a static attribute feature set and a dynamic attribute feature set, mapping the static attribute feature set to the hardware parameters of the node instance based on the feature mapping rule, mapping the dynamic attribute feature set to the software parameters of the node instance, and generating a network node instance; Design a protocol feature tensor, encode the communication protocol information between node instances into a multi-dimensional feature tensor, use a tensor decomposition method to extract implicit factors of the protocol features, build a protocol similarity measurement model based on the implicit factors, calculate the protocol compatibility matrix between node instances, and determine the connection relationship between node instances according to the compatibility threshold; A sliding time window is used to extract the business traffic time series characteristics between network node instances. The business traffic time series characteristics are analyzed based on the long short-term memory network to obtain the business traffic prediction results. A business dependency graph is constructed through service call chain analysis. The node association characteristics in the business dependency graph are extracted in combination with the graph attention network. The node resource utilization characteristics are counted based on resource monitoring data. The business traffic prediction results, node association characteristics and resource utilization characteristics are fused in multiple dimensions to calculate the business affinity. Taking business affinity as the state space and the change of connection relationship between network node instances as the action space, a reward function that considers node processing capacity constraints, link bandwidth constraints and end-to-end delay constraints is constructed. The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topology connection plan is output. The initial network topology structure is optimized through the optimal topology connection plan to generate the target network topology structure.

5. The method according to claim 4, characterized in that The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topological connection solution is output, including: A dual network architecture of value function network and policy network is constructed. The temporal difference error is used to guide the priority sampling of the experience pool and the parameters are optimized based on the policy trust region constraint. At the same time, the advantage function is used to adjust the improvement direction of the policy network and the state access distribution is introduced to guide the training of the value function network. When the optimization converges, the sequence with the highest action probability is output as the optimal topological connection solution, which includes: Obtaining the business affinity matrix and the connection state matrix of the initial network topology structure, and constructing a dual network architecture of a value function network and a policy network, wherein the value function network extracts features based on the business affinity matrix and the connection state matrix to obtain a state feature vector, and outputs a state value; the policy network extracts node association features based on the state feature vector, and outputs a node connection change action probability; Based on the state value and the reward value calculated based on the node processing capacity constraint, the link bandwidth constraint and the end-to-end delay constraint, a time difference error is calculated, the state feature vector, the node connection change action probability, the reward value and the state feature vector of the next state are stored in an experience pool as state transition information, a sampling priority is assigned to the state transition information in the experience pool based on the time difference error, training samples are obtained according to the sampling priority, and the parameters of the value function network are updated using the training samples; Constructing a policy objective function based on the action probability and state transition information of the node connection relationship change, calculating the policy gradient using the state value as a baseline function, and updating the parameters of the policy network using the policy gradient and state transition information under the policy trust region constraint; Using the temporal difference error as an advantage function, adjusting the improvement direction of the policy network based on the advantage function, generating a state access distribution using the node connection change action probability output by the policy network, and using the state access distribution for training the value function network; Monitor the changing trends of the reward value, the node connection change action probability output by the policy network, and the state value output by the value function network. When the fluctuation amplitude of the changing trend is less than the convergence threshold, extract the action sequence with the highest probability in the node connection change action probability output by the policy network as the optimal topological connection plan.

6. The method according to claim 1, characterized in that Generate resource utilization indicators based on the target network topology, build a node operating environment and deploy network services through the resource optimization solution obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from the preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair based on the fault feature sequences, and generate large-scale network node scenarios that meet the constraints of the resource optimization solution, including: Construct a multidimensional resource state space, map the CPU state vector, memory state vector, network state vector and disk state vector of the network node in the target network topology structure to the multidimensional resource state space, use an adversarial variational autoencoder to perform adversarial training on the state vector to obtain a resource state distribution, calculate the resource state entropy based on the resource state distribution, construct a loss function of the resource prediction model, use the loss function to train a recurrent neural network to obtain a resource utilization prediction model, input the historical resource state distribution into the resource utilization prediction model to generate a future resource utilization index, and set resource allocation parameters based on the resource utilization index to generate a resource optimization plan; Calculating a system stability matrix based on the resource state entropy, performing singular value decomposition on the stability matrix to obtain a characteristic mode sequence, identifying a system state mutation point based on the characteristic mode sequence, taking the system state mutation point as a fault injection moment, and constructing a node operating environment and deploying network services at the fault injection moment according to the resource optimization solution; Performing stress testing on the network service to collect system status data, mapping the system status data to a characteristic manifold using a complex variable kernel function, calculating geodesics on the characteristic manifold to obtain a fault propagation path, constructing a fault feature sequence based on the curvature characteristics of the fault propagation path, performing manifold matching on the fault feature sequence and the vulnerability features in a preset vulnerability program library, and selecting a vulnerability program with the highest matching degree and satisfying the constraints of the resource optimization solution to be implanted into the node operating environment; The characteristic manifold is analyzed by a continuous coherence method to obtain the fault duration, a repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, anomaly detection and repair of the node operating environment are performed according to the repair threshold, and when the resource utilization index of the repaired node operating environment meets the constraints of the resource optimization solution, the current node operating environment is output as a large-scale network node scenario.

7. The method according to claim 6, characterized in that The characteristic manifold is analyzed by the continuous coherence method to obtain the fault duration, and the repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, including: A nested sequence of simplex complexes is constructed on the feature manifold. The duration information of the fault feature is extracted using homology group mapping. The corrected fault duration is obtained by combining two-level feature weight optimization. The coupling matrix of fault duration and resource state entropy is established. The coupling matrix is ​​decomposed by features to obtain the repair threshold, which includes: Constructing a distance metric space on a characteristic manifold, calculating the distance value between point pairs based on the distance metric space, constructing a simplex complex using the distance value, generating a nested sequence of the simplex complex by gradually increasing the distance value, calculating the homology group mapping between adjacent simplex complexes in the nested sequence to obtain a topological characteristic sequence, extracting the appearance time and disappearance time of features in the topological characteristic sequence, calculating the feature duration based on the appearance time and disappearance time, and obtaining the fault duration by weighted summation of the feature duration; According to the structure of the simplex complex, a weight coefficient is assigned to the fault duration, the product of the weight coefficient and the fault duration is used as a dimensional eigenvalue, the dimensional eigenvalue is subjected to eigendecomposition to obtain a feature weight, and the product of the feature weight and the dimensional eigenvalue is summed to obtain a corrected fault duration; Calculate the correlation coefficient between the corrected fault duration and resource state entropy, fill the correlation coefficient into the diagonal matrix composed of the corrected fault duration and resource state entropy to obtain a coupling matrix, perform eigendecomposition on the coupling matrix to obtain eigenvectors, multiply the eigenvectors with the corrected fault duration and resource state entropy respectively and sum them to obtain a threshold judgment value, and use the threshold judgment value and the marked repair decision data to optimize to obtain a repair threshold.

8. A large-scale network node scenario construction system based on a network range, used to implement the method described in any one of claims 1 to 7, characterized in that: include: The first unit is used to calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; The second unit is used to calculate the node distribution density threshold using a graph clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain an initial network topology structure, generate a network node instance from a target network node template through attribute mapping, build a connection relationship between network node instances based on inter-node communication protocol information, extract communication features between network node instances and calculate service affinity, optimize the initial network topology structure based on service affinity, and generate a target network topology structure; The third unit is used to generate resource utilization indicators according to the target network topology, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate a fault feature sequence, select matching vulnerability programs from a preset vulnerability program library based on the fault feature sequence and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.

9. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method described in any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Network attack target identification method and network attack target identification system based on attack graph

    CN108418843A

  • SDN intelligent multicast routing method based on deep layered reinforcement learning

    CN117201396A

  • Selectively Choosing Between Actual-Attack and Simulation / Evaluation for Validating a Vulnerability of a Network Node During Execution of a Penetration Testing Campaign

    US20190149572A1

  • A smart password implementation method, apparatus, electronic device and computer-readable medium

    US20240031356A1

  • System and method for graphical reticulated attack vectors for internet of things aggregate security (gravitas)

    WO2022066551A1

Cited By

  • Automatic vulnerability processing method and system

    CN120180454A

  • Dynamic evolution password practical training range system and password practical training scene generation method

    CN120263566A

  • Dynamic Evolution of Password Training Range System and Method for Generating Password Training Scenarios

    CN120263566B

  • Method and system for cross-service unified topological data structure and operation in network target range

    CN120301931A

  • Multi-dimensional scene intelligent safety test method and device for unmanned driving

    CN120524998A