Method and System for Constructing Large-Scale Network Node Scenarios Based on a Network Range
By calculating the vulnerability correlation and service affinity between network nodes and optimizing the network topology structure, the problem that network node scenario structure in the prior art is difficult to meet large-scale needs, and efficient network node scenario structure and resource utilization are achieved.
Patent Information
- Application Number
- CN202510450817.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The network node scenario structure in existing network shooting ranges is difficult to meet large-scale needs, and the vulnerability correlation and business correlation between nodes are insufficiently considered, resulting in low scenario authenticity and resource utilization efficiency.
By calculating the correlation between vulnerabilities between network nodes, dividing offensive and defense levels, generating an offensive and defense level node distribution map, and filtering the target network node template. The graph theory clustering algorithm is used to optimize the network topology, and the initial topology is optimized based on the business affinity to generate the target network topology.
The automated construction of large-scale network node scenarios is realized, the authenticity of the scene and resource utilization efficiency are ensured, and the training effect of network offensive and defense confrontation is improved.
Smart Images

Figure CN119996079B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to network security technologies, and in particular, to a method and system for constructing a large-scale network node scenario based on a network range. Background Art
[0002] As an important platform for network security research, the authenticity and scale of the network node scenario construction in a network range directly affect the training effect of attack and defense confrontation. The construction of network node scenarios in existing network ranges mainly relies on manual configuration, which is difficult to meet the requirements of large-scale scenario construction, and the vulnerability correlation and service correlation between nodes are insufficiently considered.
[0003] As the scale of the network range continues to expand, the number of network nodes grows exponentially. The traditional manual configuration method has problems such as a large workload and low configuration efficiency. At the same time, due to the lack of quantitative analysis of the vulnerability propagation characteristics and service affinity between nodes, it is difficult to ensure the authenticity of the constructed scenario, affecting the network attack and defense confrontation effect.
[0004] Existing network node scenario construction methods mainly focus on the function implementation of individual nodes, insufficiently consider the correlation between nodes and the resource utilization efficiency, and it is difficult to achieve the adaptive optimization of the network topology structure and the reasonable allocation of resources. Therefore, there is an urgent need for a method that can automatically construct a large-scale network node scenario and ensure the authenticity of the scenario and the resource utilization efficiency. Summary of the Invention
[0005] Embodiments of the present invention provide a method and system for constructing a large-scale network node scenario based on a network range, which can solve the problems in the prior art.
[0006] In the first aspect of the embodiments of the present invention,
[0007] A method for constructing a large-scale network node scenario based on a network range is provided, including:
[0008] Calculating the vulnerability correlation degree between nodes in the network node scenario construction requirement, dividing the network nodes into multiple attack and defense levels, generating a distribution map of attack and defense level nodes, extracting candidate network node templates from a network node template library and calculating the vulnerability chain propagation coefficient, and matching the vulnerability chain propagation coefficient with the distribution map of attack and defense level nodes to screen out target network node templates;
[0009] The graph theory clustering algorithm is used to calculate the node distribution density threshold and hierarchically optimize the network topology type in the network node scenario construction requirements to obtain the initial network topology structure. The target network node template is used to generate network node instances through attribute mapping. The connection relationship between network node instances is constructed based on the inter-node communication protocol information. The communication characteristics between network node instances are extracted and the service affinity is calculated. The initial network topology structure is optimized based on the service affinity to generate the target network topology structure;
[0010] The resource utilization index is generated according to the target network topology structure. The node operating environment is constructed and the network service is deployed through the resource optimization plan obtained by predicting the resource utilization index. The stress test is performed on the network service to generate a fault feature sequence. Based on the fault feature sequence, the matching vulnerability program is selected from the preset vulnerability program library and implanted into the node operating environment. The status information in the node operating environment is monitored and anomaly detection and repair are performed according to the fault feature sequence to generate a large-scale network node scenario that meets the constraints of the resource optimization plan.
[0011] In an alternative embodiment,
[0012] Calculate the vulnerability correlation degree between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, and match the vulnerability chain propagation coefficient with the attack and defense level node distribution map. The screened target network node templates include:
[0013] Construct a node association graph according to the vulnerability correlation degree between nodes, divide the node association graph based on the community discovery algorithm to generate an attack and defense level node distribution map, introduce the vulnerability exploitation chain and calculate the trigger probability of adjacent vulnerabilities and the attack chain length attenuation coefficient, and match them with the vulnerability intensity values at the corresponding positions in the attack and defense level node distribution map. Select the candidate network node template with the minimum matching degree value as the target network node template, specifically including:
[0014] Obtain the vulnerability attribute information of the network node to generate a node vulnerability feature vector, calculate the distance attenuation function value based on the inter-node communication hop count, perform tensor operation on the node vulnerability feature vector and the distance attenuation function value to obtain a node vulnerability combination matrix, and calculate the vulnerability correlation degree between nodes in the network node scenario construction requirements based on the node vulnerability combination matrix;
[0015] Construct a node association graph with the vulnerability correlation degree as the edge weight, perform iterative partitioning on the node association graph using the community discovery algorithm, divide the network nodes into multiple attack and defense levels, and calculate the hierarchical vulnerability intensity value for each attack and defense level;
[0016] Generate a distribution map of attack and defense layer nodes based on the hierarchical position relationship and hierarchical vulnerability strength values of the attack and defense layers, where nodes represent attack and defense layers, and the connecting edges between nodes represent the vulnerability strength relationship between layers;
[0017] Extract candidate network node templates from a preset network node template library. Based on the vulnerability characteristics in the candidate network node templates, establish the connection relationship between vulnerabilities through the system state requirements, state changes, and attack entry types in the vulnerability characteristics. Introduce the continuity of system state changes as a screening condition for the vulnerability exploitation chain, and combine the cascade trigger probability and length decay coefficient of the attack chain to calculate the vulnerability chain propagation coefficient;
[0018] Match the vulnerability chain propagation coefficient with the vulnerability strength value at the corresponding position in the attack and defense layer node distribution map to calculate the propagation coefficient deviation value. Calculate the change in hierarchical vulnerability strength after deployment based on the candidate network node template, and determine the weighted sum of the propagation coefficient deviation value and the change in hierarchical vulnerability strength as the matching degree value. Select the candidate network node template with the smallest matching degree value as the target network node template.
[0019] In an alternative embodiment,
[0020] Establish the connection relationship between vulnerabilities through the system state requirements, state changes, and attack entry types in the vulnerability characteristics. Introduce the continuity of system state changes as a screening condition for the vulnerability exploitation chain, and combine the cascade trigger probability and length decay coefficient of the attack chain to calculate the vulnerability chain propagation coefficient, including:
[0021] Extract vulnerability characteristics from the candidate network node template. The vulnerability characteristics include the system state requirements for vulnerability triggering, the system state changes after vulnerability exploitation, and the attack entry types for vulnerability exploitation, and construct a vulnerability characteristic vector;
[0022] Perform feature matching according to the system state requirements, system state changes, and attack entry types in the vulnerability characteristic vector. When the system state change of the first vulnerability meets the system state requirements of the second vulnerability, and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability, establish a connection relationship between the two vulnerabilities;
[0023] Construct a vulnerability dependency graph based on the connection relationship, use the depth-first search method to identify the vulnerability exploitation chain path in the vulnerability dependency graph, and screen the vulnerability exploitation chain path according to the continuity of system state changes in the vulnerability characteristic vector to generate a vulnerability exploitation chain;
[0024] Calculate the connection distance between adjacent nodes based on the number of nodes in the vulnerability exploitation chain, calculate the path length of the vulnerability exploitation chain according to the connection distance, substitute the path length into the exponential decay function to obtain the attack chain length decay coefficient of the vulnerability exploitation chain;
[0025] For adjacent vulnerabilities in the vulnerability exploitation chain, perform a consecutive multiplication operation on the triggering probabilities of adjacent vulnerabilities in the order of connection of vulnerabilities in the vulnerability exploitation chain to obtain the cascading triggering probability of the vulnerability exploitation chain, and multiply the cascading triggering probability by the attack chain length decay coefficient to obtain the vulnerability chain propagation coefficient;
[0026] Construct an attack path graph based on the vulnerability feature vector and the vulnerability exploitation chain, map the vulnerability exploitation chain to an attack path, statistically count the number of successful attacks of the attack path through multiple simulations, optimize the calculation parameters of the triggering probability and the attack chain length decay coefficient using the number of successful attacks of the attack path, and recalculate the vulnerability chain propagation coefficient using the optimized parameters to obtain the final vulnerability chain propagation coefficient.
[0027] In an alternative embodiment,
[0028] Adopt a graph theory clustering algorithm to calculate the node distribution density threshold and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain an initial network topology structure. Generate network node instances by attribute mapping of the target network node template, construct the connection relationship between network node instances based on the inter-node communication protocol information, extract the communication characteristics between network node instances and calculate the service affinity, and optimize the initial network topology structure based on the service affinity to generate the target network topology structure, including:
[0029] Construct a distance matrix based on the Euclidean distance between nodes, calculate the node local density and relative density using a graph theory clustering algorithm based on the distance matrix, set a density threshold in combination with the network node scenario construction requirements, perform normalization processing on the node local density and relative density to obtain the node comprehensive density value, perform hierarchical division on the nodes according to the network topology hierarchical requirements, determine the topological connection relationship of the nodes in each layer based on the comprehensive density value, and obtain the initial network topology structure that meets the hierarchical constraints through iterative optimization;
[0030] Extract the hardware configuration information and software configuration information from the target network node template, construct a static attribute feature set and a dynamic attribute feature set, map the static attribute feature set to the hardware parameters of the node instance based on the feature mapping rule, map the dynamic attribute feature set to the software parameters of the node instance, and generate network node instances;
[0031] Design a protocol feature tensor, encode the communication protocol information between node instances into a multi-dimensional feature tensor, use the tensor decomposition method to extract the latent factors of the protocol features, construct a protocol similarity metric model based on the latent factors, calculate the protocol compatibility matrix between node instances, and determine the connection relationship between node instances according to the compatibility threshold;
[0032] Extract the time series features of the service traffic between network node instances using a sliding time window, analyze the time series features of the service traffic based on a long short-term memory network to obtain a service traffic prediction result, construct a service dependency graph through service call chain analysis, combine a graph attention network to extract the node association features in the service dependency graph, and statistically calculate the node resource utilization features based on resource monitoring data. Perform multi-dimensional feature fusion on the service traffic prediction result, node association features, and resource utilization features to calculate the service affinity;
[0033] Use the service affinity as the state space and the change in the connection relationship between network node instances as the action space. Construct a reward function considering node processing capacity constraints, link bandwidth constraints, and end-to-end delay constraints. Use the deep reinforcement learning method to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithms. When the reward function converges, output the optimal topology connection scheme, and optimize the initial network topology structure through the optimal topology connection scheme to generate the target network topology structure.
[0034] In an alternative embodiment,
[0035] Using the deep reinforcement learning method to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithms, and outputting the optimal topology connection scheme when the reward function converges includes:
[0036] Construct a dual network architecture of a value function network and a policy network. Use temporal difference error to guide the priority sampling of the experience pool and optimize the parameters based on the policy confidence domain constraint. At the same time, use the advantage function to adjust the improvement direction of the policy network and introduce the state access distribution to guide the training of the value function network. When the optimization converges, output the sequence with the highest action probability as the optimal topology connection scheme, specifically including:
[0037] Obtain the service affinity matrix and the connection state matrix of the initial network topology structure, and construct a dual network architecture of a value function network and a policy network. Among them, the value function network extracts state feature vectors based on the service affinity matrix and the connection state matrix and outputs state values; the policy network extracts the association features between nodes based on the state feature vectors and outputs the node connection change action probability;
[0038] Calculate the temporal difference error based on the state value and the reward value calculated based on the node processing capacity constraint, link bandwidth constraint, and end-to-end delay constraint. Store the state feature vector, node connection change action probability, reward value, and state feature vector of the next state as state transition information in the experience pool. Allocate sampling priorities to the state transition information in the experience pool based on the temporal difference error, obtain training samples according to the sampling priorities, and update the parameters of the value function network using the training samples;
[0039] Construct a policy objective function based on the action probability of the node connection relationship change and the state transition information. Calculate the policy gradient using the state value as the baseline function, and update the parameters of the policy network using the policy gradient and state transition information under the constraint of the policy confidence domain;
[0040] Use the temporal difference error as the advantage function, adjust the improvement direction of the policy network based on the advantage function, generate a state access distribution using the node connection change action probability output by the policy network, and use the state access distribution for the training of the value function network;
[0041] Monitor the change trends of the reward value, the node connection change action probability output by the policy network, and the state value output by the value function network. When the fluctuation amplitude of the change trend is less than the convergence threshold, extract the action sequence with the highest probability in the node connection change action probability output by the policy network as the optimal topology connection scheme.
[0042] In an alternative embodiment,
[0043] Generate a resource utilization index according to the target network topology structure, construct a node operating environment and deploy network services through a resource optimization scheme obtained by predicting the resource utilization index, perform a stress test on the network services to generate a fault feature sequence, select a matching vulnerability program from a preset vulnerability program library based on the fault feature sequence and implant it into the node operating environment, monitor the state information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization scheme, including:
[0044] Construct a multi-dimensional resource state space, map the CPU state vector, memory state vector, network state vector, and disk state vector of the network nodes in the target network topology structure to the multi-dimensional resource state space, perform adversarial training on the state vectors using an adversarial variational autoencoder to obtain a resource state distribution, calculate the resource state entropy based on the resource state distribution, construct a loss function for the resource prediction model, train a recurrent neural network using the loss function to obtain a resource utilization prediction model, input the historical resource state distribution into the resource utilization prediction model to generate future resource utilization indices, and set resource allocation parameters based on the resource utilization indices to generate a resource optimization scheme;
[0045] Calculate the system stability matrix based on the resource state entropy, perform singular value decomposition on the stability matrix to obtain a sequence of eigenmodes, identify the system state mutation points based on the sequence of eigenmodes, use the system state mutation points as the fault injection moments, and construct a node operating environment and deploy network services at the fault injection moments according to the resource optimization plan;
[0046] Conduct a stress test on the network service to collect system state data, map the system state data to a feature manifold using a complex variable kernel function, calculate the geodesic on the feature manifold to obtain the fault propagation path, calculate the curvature features based on the fault propagation path to construct a fault feature sequence, and perform manifold matching between the fault feature sequence and the vulnerability features in a preset vulnerability program library, and select the vulnerability program with the highest matching degree and meeting the constraints of the resource optimization plan to implant into the node operating environment;
[0047] Analyze the feature manifold using persistent homology method to obtain the fault duration, construct a repair threshold based on the coupling relationship between the resource state entropy and the fault duration, perform anomaly detection and repair on the node operating environment according to the repair threshold, and when the resource utilization rate index of the repaired node operating environment meets the constraints of the resource optimization plan, output the current node operating environment as a large-scale network node scenario.
[0048] In an alternative embodiment,
[0049] Analyze the feature manifold using persistent homology method to obtain the fault duration, and constructing a repair threshold based on the coupling relationship between the resource state entropy and the fault duration includes:
[0050] Construct a nested sequence of simplicial complexes on the feature manifold, use the homology group mapping to extract the duration information of the fault features, combine two-level feature weights optimization to obtain a corrected fault duration, establish a coupling matrix between the fault duration and the resource state entropy, and perform eigenvalue decomposition on the coupling matrix to obtain the repair threshold, specifically including:
[0051] Construct a distance metric space on the feature manifold, calculate the distance values between point pairs based on the distance metric space, use the distance values to construct a simplicial complex, generate a nested sequence of the simplicial complexes by gradually increasing the distance values, calculate the homology group mapping between adjacent simplicial complexes in the nested sequence to obtain a topological feature sequence, extract the appearance time and disappearance time of the features in the topological feature sequence, calculate the feature duration based on the appearance time and disappearance time, and sum the weighted feature durations to obtain the fault duration;
[0052] Assign a weighting coefficient to the fault duration according to the structure of the simplex complex, take the product of the weighting coefficient and the fault duration as the dimensional eigenvalue, perform eigen-decomposition on the dimensional eigenvalue to obtain the eigen-weight, and sum the product of the eigen-weight and the dimensional eigenvalue to obtain the corrected fault duration;
[0053] Calculate the correlation coefficient between the corrected fault duration and the resource state entropy, fill the correlation coefficient into the diagonal matrix composed of the corrected fault duration and the resource state entropy to obtain the coupling matrix, perform eigen-decomposition on the coupling matrix to obtain the eigenvector, multiply the eigenvector by the corrected fault duration and the resource state entropy respectively and sum to obtain the threshold decision value, and optimize the threshold decision value with the marked repair decision data to obtain the repair threshold.
[0054] In the second aspect of the embodiments of the present invention,
[0055] Provide a large-scale network node scenario construction system based on a network range, including:
[0056] The first unit is used to calculate the vulnerability correlation degree between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template;
[0057] The second unit is used to calculate the node distribution density threshold by using the graph theory clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain the initial network topology structure, generate network node instances by attribute mapping of the target network node template, construct the connection relationship between network node instances based on the inter-node communication protocol information, extract the communication characteristics between network node instances and calculate the service affinity, and optimize the initial network topology structure based on the service affinity to generate the target network topology structure;
[0058] The third unit is used to generate resource utilization rate indicators according to the target network topology structure, construct a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization rate indicators, perform stress testing on the network services to generate a fault feature sequence, select a matching vulnerability program from the preset vulnerability program library based on the fault feature sequence and implant it into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.
[0059] In the third aspect of the embodiments of the present invention,
[0060] Provide an electronic device, including:
[0061] Processor;
[0062] A memory for storing instructions executable by the processor;
[0063] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0064] In the fourth aspect of the embodiments of the present invention,
[0065] A computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0066] In this embodiment, by constructing a distribution map of attack and defense hierarchical nodes, accurately depicting the vulnerability association relationship between network nodes, and improving the simulation ability of the network range for complex network attack and defense environments. By calculating the vulnerability chain propagation coefficient and optimizing the network topology structure in combination with the graph theory clustering algorithm, the rationality of the vulnerability propagation path can be effectively improved, making the drills of network attack and defense strategies more realistic and targeted. Using the business affinity analysis method to optimize the initial network topology structure makes the communication relationship between network nodes more in line with the actual business scenario and improves the accuracy of the simulation network. At the same time, combining resource utilization prediction to optimize the node operating environment can realize the dynamic construction of large-scale network nodes on the premise of ensuring the efficient use of computing resources in the network range, and enhance the scalability and applicability of the network range. By generating a fault feature sequence through stress testing and performing vulnerability program matching and implantation based on this sequence, the impact of network attacks on service operation can be effectively simulated, and the accuracy of vulnerability reproduction can be improved. In addition, combining the anomaly detection and repair mechanism can quickly respond to the abnormal state in the network environment, enhance the stability and security of the network service, and thus construct a more realistic and intelligent large-scale network range environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 It is a schematic flowchart of a method for constructing a large-scale network node scenario based on a network range in an embodiment of the present invention;
[0068] Figure 2 It is a comparison chart of the prediction accuracy of the success rate of vulnerability chain utilization in an embodiment of the present invention;
[0069] Figure 3 It is a comparison chart of the link load distribution before and after optimization in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0070] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0071] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments may be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0072] Figure 1 The flowchart of the method for constructing a large-scale network node scenario based on a network range for an embodiment of the present invention is shown as Figure 1 shown, and the method includes:
[0073] S101. Calculate the vulnerability correlation degree between nodes in the construction requirements of the network node scenario, divide the network nodes into multiple attack and defense levels, generate a node distribution map of the attack and defense levels, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the node distribution map of the attack and defense levels, and screen out the target network node templates;
[0074] S102. Use the graph theory clustering algorithm to calculate the node distribution density threshold and perform hierarchical optimization on the network topology type in the construction requirements of the network node scenario to obtain the initial network topology structure, generate network node instances by attribute mapping of the target network node templates, construct the connection relationship between network node instances based on the inter-node communication protocol information, extract the communication characteristics between network node instances and calculate the service affinity, and optimize the initial network topology structure based on the service affinity to generate the target network topology structure;
[0075] S103. Generate resource utilization indicators according to the target network topology structure, construct a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform a stress test on the network services to generate a fault feature sequence, select a matching vulnerability program from the preset vulnerability program library based on the fault feature sequence and implant it into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.
[0076] In an alternative embodiment, calculate the vulnerability correlation degree between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, and match the vulnerability chain propagation coefficient with the attack and defense level node distribution map. The screened target network node templates include:
[0077] Construct a node association graph based on the vulnerability correlation degree between nodes, divide the node association graph based on the community discovery algorithm, generate an attack and defense level node distribution map, introduce the vulnerability exploitation chain and calculate the trigger probability of adjacent vulnerabilities and the attack chain length attenuation coefficient, and match them with the vulnerability intensity values at the corresponding positions in the attack and defense level node distribution map. Select the candidate network node template with the minimum matching degree value as the target network node template, specifically including:
[0078] Obtain the vulnerability attribute information of the network nodes to generate node vulnerability feature vectors, calculate the distance attenuation function value based on the communication hop count between nodes, perform tensor operations on the node vulnerability feature vectors and the distance attenuation function value to obtain a node vulnerability combination matrix, and calculate the vulnerability correlation degree between nodes in the network node scenario construction requirements based on the node vulnerability combination matrix;
[0079] Construct a node association graph with the vulnerability correlation degree as the edge weight, iteratively divide the node association graph using the community discovery algorithm, divide the network nodes into multiple attack and defense levels, and calculate the hierarchical vulnerability intensity value for each attack and defense level;
[0080] Generate an attack and defense level node distribution map based on the hierarchical position relationship and hierarchical vulnerability intensity value of the attack and defense levels. Among them, the nodes represent the attack and defense levels, and the connecting edges between the nodes represent the vulnerability intensity relationship between the levels;
[0081] Extract candidate network node templates from the preset network node template library, establish the connection relationship between vulnerabilities based on the vulnerability characteristics in the candidate network node templates, introduce the continuity of system state changes as the screening condition for the vulnerability exploitation chain, and combine the cascading trigger probability and length attenuation coefficient of the attack chain to calculate the vulnerability chain propagation coefficient;
[0082] Match the vulnerability chain propagation coefficient with the vulnerability intensity value at the corresponding position in the attack and defense level node distribution map to calculate the propagation coefficient deviation value, calculate the hierarchical vulnerability intensity change amount after deployment based on the candidate network node template, and determine the weighted sum of the propagation coefficient deviation value and the hierarchical vulnerability intensity change amount as the matching degree value. Select the candidate network node template with the minimum matching degree value as the target network node template.
[0083] Exemplarily, obtain the vulnerability attribute information of all network nodes in the scenario to be constructed, such as vulnerability type, CVE number, CVSS score, affected software version, etc. Convert this vulnerability attribute information into a numerical feature vector. For example, use one-hot encoding to represent the vulnerability type and use the numerical value of the CVSS score to represent the vulnerability severity, etc. Suppose there are two nodes. The vulnerability feature vector of node A is [1, 0, 7.5], indicating the existence of vulnerability type 1, the non-existence of vulnerability type 2, and the CVSS score is 7.5; the vulnerability feature vector of node B is [0, 1, 9.0], indicating the non-existence of vulnerability type 1, the existence of vulnerability type 2, and the CVSS score is 9.0.
[0084] Calculate the distance attenuation function value between nodes. This function value is used to measure the impact of the communication distance between nodes on the vulnerability correlation degree. For example, a hop-count-based attenuation function can be used. The more hops, the greater the attenuation value. Suppose the communication hop count between node A and node B is 2, and the attenuation function is 1 / hop count, then the attenuation value is 0.5.
[0085] Perform an operation on the vulnerability feature vector of the node and the distance attenuation function value to obtain the node vulnerability combination matrix. This matrix reflects the strength of the vulnerability correlation between nodes.
[0086] For example, the element values of the vulnerability combination matrix of node A and node B are [1×0.5, 0×0.5, 7.5×0.5, 0×0.5, 1×0.5, 9.0×0.5] = [0.5, 0, 3.75, 0, 0.5, 4.5].
[0087] Calculate the vulnerability correlation degree between nodes based on the node vulnerability combination matrix. For example, the element values of the combination matrix can be weighted and summed to obtain the vulnerability correlation degree between node A and node B as 8.75.
[0088] Use the calculated vulnerability correlation degree as the edge weight to construct a node association graph. The nodes in the graph represent network nodes, the edges represent the vulnerability correlation relationships between nodes, and the edge weights represent the correlation strength.
[0089] Adopt a community discovery algorithm to iteratively partition the node association graph and divide the network nodes into multiple attack and defense levels. For example, the Louvain algorithm can be used for community discovery. Suppose the network nodes are divided into three levels, namely the core layer, the business layer, and the boundary layer.
[0090] Calculate the vulnerability strength value of each attack and defense level. For example, the average value of the CVSS scores of all nodes within the level can be used as the vulnerability strength value of the level. Suppose the vulnerability strength value of the core layer is 8.0, the vulnerability strength value of the business layer is 7.0, and the vulnerability strength value of the boundary layer is 6.0.
[0091] Generate a distribution map of attack and defense level nodes based on the hierarchical position relationship and hierarchical vulnerability intensity value at the attack and defense levels. The nodes in the figure represent the attack and defense levels, and the connections between the nodes represent the vulnerability intensity relationship between the levels. For example, the core layer is connected to the business layer, and the value on the connection line is the difference of 1.0 between 8.0 and 7.0, indicating the potential threat level of the core layer to the business layer.
[0092] Extract candidate network node templates from a preset network node template library. For example, the template library contains different types of node templates such as Web servers, database servers, and mail servers.
[0093] Based on the vulnerability characteristics in the candidate network node templates, establish the connection relationship between vulnerabilities through the system state requirements, state changes, and attack entry types in the vulnerability characteristics. For example, if the attack result of one vulnerability is the trigger condition of another vulnerability, then these two vulnerabilities can be connected to form an attack chain. Introduce the continuity of system state changes as a screening condition for the vulnerability exploitation chain. For example, only vulnerabilities with continuous state changes can form an effective attack chain. Combine the cascade trigger probability of the attack chain with the length attenuation coefficient to calculate the vulnerability chain propagation coefficient. For example, an attack chain containing three vulnerabilities, with the trigger probabilities of each vulnerability being 0.8, 0.9, and 0.7 respectively, and the length attenuation coefficient being 0.5, then the vulnerability chain propagation coefficient is 0.8×0.9×0.7×0.5 = 0.252.
[0094] Match the vulnerability chain propagation coefficient with the vulnerability intensity value at the corresponding position in the attack and defense level node distribution map to calculate the propagation coefficient deviation value. For example, compare the vulnerability chain propagation coefficient of the Web server template with the boundary layer vulnerability intensity value of 6.0 to obtain the deviation value. Calculate the change amount of the hierarchical vulnerability intensity after deployment based on the candidate network node template. For example, after deploying the Web server template, the boundary layer vulnerability intensity value may change from 6.0 to 7.0, and the change amount is 1.0. Determine the weighted sum of the propagation coefficient deviation value and the hierarchical vulnerability intensity change amount as the matching degree value. Select the candidate network node template with the minimum matching degree value as the target network node template.
[0095] In this embodiment, by accurately calculating the vulnerability correlation degree between network nodes, a distribution map of attack and defense hierarchical nodes is constructed, making the attack and defense structure of the network range more realistic and hierarchical. The community discovery algorithm is used to partition the node correlation graph to ensure the rationality of the attack and defense levels, improve the accuracy of attack path analysis, and by calculating the trigger probability and attenuation coefficient of the vulnerability exploitation chain, the propagation characteristics of vulnerabilities in the network can be effectively characterized. By combining the distance attenuation function of the node vulnerability feature vector and the communication hop count, the vulnerability correlation degree is accurately measured, and the tensor calculation method is used to improve the calculation efficiency, making the network scenario construction more efficient and intelligent. Introducing the continuity of system state changes as a screening condition for the vulnerability exploitation chain can more accurately evaluate the feasibility of the attack path and ensure that the selected network node template can truly reflect the dynamic process of vulnerability propagation. By matching the vulnerability chain propagation coefficient with the vulnerability strength value at the attack and defense levels, the optimal adaptation of the selected target network node template in terms of vulnerability propagation impact is ensured, thereby improving the simulation accuracy of the network range. A weighted matching mechanism of the propagation coefficient deviation value and the change amount of the hierarchical vulnerability strength is adopted to adaptively optimize the deployment strategy of network nodes, improve the rationality of vulnerability simulation, and make the finally generated network range more accurately reflect the propagation characteristics of the attack chain in the real network environment.
[0096] In an alternative implementation, connection relationships between vulnerabilities are established through the system state requirements, state changes, and attack entry types in the vulnerability features. The continuity of system state changes is introduced as a screening condition for the vulnerability exploitation chain, and the cascade trigger probability of the attack chain is combined with the length attenuation coefficient to calculate the vulnerability chain propagation coefficient, including:
[0097] Extract vulnerability features from the candidate network node templates. The vulnerability features include the system state requirements for vulnerability triggering, the system state changes after vulnerability exploitation, and the attack entry types for vulnerability exploitation, and construct a vulnerability feature vector;
[0098] Perform feature matching according to the system state requirements, system state changes, and attack entry types in the vulnerability feature vector. When the system state change of the first vulnerability meets the system state requirements of the second vulnerability, and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability, a connection relationship is established between the two vulnerabilities;
[0099] Based on the connection relationship, construct a vulnerability dependency graph. Use the depth-first search method to identify the vulnerability exploitation chain path in the vulnerability dependency graph, and screen the vulnerability exploitation chain path according to the continuity of the system state changes in the vulnerability feature vector to generate a vulnerability exploitation chain;
[0100] Calculate the connection distance between adjacent nodes based on the number of nodes in the vulnerability exploitation chain, calculate the path length of the vulnerability exploitation chain according to the connection distance, substitute the path length into the exponential decay function to obtain the attack chain length attenuation coefficient of the vulnerability exploitation chain;
[0101] For adjacent vulnerabilities in the vulnerability exploitation chain, perform a consecutive multiplication operation on the trigger probabilities of adjacent vulnerabilities in the order of connection of vulnerabilities in the vulnerability exploitation chain to obtain the cascade trigger probability of the vulnerability exploitation chain, and multiply the cascade trigger probability by the attack chain length attenuation coefficient to obtain the vulnerability chain propagation coefficient;
[0102] Construct an attack path graph based on the vulnerability feature vector and the vulnerability exploitation chain, map the vulnerability exploitation chain to an attack path, statistically count the number of successful times of the attack path through multiple simulations, optimize the calculation parameters of the trigger probability and the attack chain length attenuation coefficient using the number of successful times of the attack path, and recalculate the vulnerability chain propagation coefficient using the optimized parameters to obtain the final vulnerability chain propagation coefficient.
[0103] Exemplarily, extract vulnerability features from the candidate network node template to construct a vulnerability feature vector. The vulnerability features include the system state requirements for vulnerability triggering, the system state changes after vulnerability exploitation, and the attack entry type for vulnerability exploitation. For example, the feature vector of a certain vulnerability can be expressed as: the system state requirement is "Web service is enabled", the system state change is "obtain WebShell permission", and the attack entry type is "remote code execution".
[0104] Perform feature matching according to the vulnerability feature vector to establish the connection relationship between vulnerabilities. When the system state change of the first vulnerability meets the system state requirements of the second vulnerability, and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability, a connection relationship is established between the two vulnerabilities. For example, the system state change of vulnerability A is "obtain WebShell permission", the system state requirement of vulnerability B is "WebShell permission", and the attack entry type of vulnerability B is "local command execution", and vulnerability A introduces the attack entry of "local command execution", then a connection relationship can be established between vulnerability A and vulnerability B.
[0105] Construct a vulnerability dependency graph based on the connection relationship between vulnerabilities. The vulnerability dependency graph is a directed graph, where nodes represent vulnerabilities and edges represent the connection relationship between vulnerabilities. Use the depth-first search method to identify the vulnerability exploitation chain path in the vulnerability dependency graph. For example, in the vulnerability dependency graph, if there is a path from vulnerability A to vulnerability B and then to vulnerability C, this path is a vulnerability exploitation chain path.
[0106] Screen the exploit chain path according to the continuity of system state changes to generate an exploit chain. The continuity of system state changes means that the system state changes of adjacent vulnerabilities in the exploit chain need to conform to a logical order. For example, if the system state change of vulnerability A is "obtain WebShell permission" and the system state change of vulnerability B is "escalate privileges to administrator permission", then the system state changes of these two vulnerabilities are continuous. Conversely, if the system state change of vulnerability A is "obtain WebShell permission" and the system state change of vulnerability B is "denial of service", then the system state changes of these two vulnerabilities are discontinuous, and this exploit chain path needs to be screened out.
[0107] Calculate the attack chain length attenuation coefficient of the exploit chain. Based on the number of nodes in the exploit chain, calculate the connection distance between adjacent nodes. The connection distance can be evaluated according to factors such as the difficulty of exploitation and the time required. For example, if the exploitation difficulty between vulnerability A and vulnerability B is high, then their connection distance is large. Calculate the path length of the exploit chain according to the connection distance. The path length is the sum of all connection distances. Substitute the path length into the exponential decay function to obtain the attack chain length attenuation coefficient. The longer the path length, the smaller the attenuation coefficient. For example, the attenuation coefficient with a path length of 3 may be 0.8, and the attenuation coefficient with a path length of 5 may be 0.5.
[0108] Calculate the cascading trigger probability of the exploit chain. For adjacent vulnerabilities in the exploit chain, in the connection order of the vulnerabilities in the exploit chain, successively perform a multiplication operation on the trigger probabilities of adjacent vulnerabilities to obtain the cascading trigger probability of the exploit chain. For example, if the trigger probability of vulnerability A is 0.8 and the trigger probability of vulnerability B is 0.9, then the cascading trigger probability of the exploit chain composed of vulnerability A and vulnerability B is 0.8×0.9 = 0.72.
[0109] Multiply the cascading trigger probability by the attack chain length attenuation coefficient to obtain the vulnerability chain propagation coefficient. For example, if the cascading trigger probability is 0.72 and the attack chain length attenuation coefficient is 0.8, then the vulnerability chain propagation coefficient is 0.72×0.8 = 0.576.
[0110] Construct an attack path graph based on the vulnerability feature vector and the exploit chain, and map the exploit chain to an attack path. Through multiple simulations, count the number of successful times of the attack path, and use the number of successful times of the attack path to optimize the calculation parameters of the trigger probability and the attack chain length attenuation coefficient. Recalculate the vulnerability chain propagation coefficient using the optimized parameters to obtain the final vulnerability chain propagation coefficient.
[0111] Figure 2This is a comparison chart of the prediction accuracy of the exploitation success rate of vulnerability chains in the embodiments of the present invention. This chart compares the differences between the exploitation success rates of vulnerability chains predicted by different methods and the actual observed values. The data shows that the average deviation between the predicted values and the actual observed values of the present technical solution is only 4.2%, while the average deviations of the CVSS attack chain evaluation method, the multi-step attack graph analysis method, and the traditional Bayesian network method are 12.8%, 9.6%, and 15.3% respectively. Especially in the medium-complexity scenario, the predicted value of the present technical solution is 68.5%, the actual observed value is 65.2%, and the deviation is only 3.3%; while the predicted values of other methods are 55.6%, 76.4%, and 48.9% respectively, and the deviations are significantly larger. This indicates that the present technical solution significantly improves the prediction accuracy of the exploitation success rate of vulnerability chains through multiple simulation statistics and parameter optimization. It should be noted that the CVSS method and the Bayesian network method usually underestimate the exploitation success rate of vulnerability chains, while the multi-step attack graph analysis method tends to overestimate, and these deviations may lead to misallocation of security resources. The present technical solution effectively overcomes these deviations by introducing the continuity of system state changes as a screening condition and combining multiple simulation statistics for parameter optimization, providing a more reliable decision-making basis for security defense.
[0112] In this embodiment, by matching the system state requirements, state changes, and attack entry types, it is ensured that the construction of the vulnerability exploitation chain conforms to the logic of the actual attack path, making the vulnerability propagation path more accurate. The depth-first search method is used to identify vulnerability exploitation chains in the vulnerability dependency graph, and the continuity of system state changes is introduced as a screening condition to effectively eliminate unreasonable attack paths and improve the reliability of vulnerability propagation analysis. By calculating the length decay coefficient of the attack chain and combining the product operation of vulnerability trigger probabilities, the chained propagation ability of vulnerabilities is accurately evaluated, avoiding misjudgments caused by traditional methods ignoring the attack path decay effect. In addition, the success times of attack paths are statistically simulated multiple times to optimize the calculation parameters of trigger probabilities and decay coefficients, making the vulnerability propagation model closer to the real network attack environment and improving the accuracy of vulnerability propagation risk assessment. It can effectively screen out the most valuable vulnerability exploitation chains, optimize the analysis of vulnerability propagation paths, enhance the scientific nature of network security assessment and defense strategy formulation, provide a more realistic attack chain simulation for offensive and defensive drills in the network range, and improve the pertinence and practicality of the security research and defense system.
[0113] In an alternative embodiment, a graph theory clustering algorithm is used to calculate the node distribution density threshold and hierarchically optimize the network topology type in the network node scenario construction requirements to obtain an initial network topology structure. The target network node template is used to generate network node instances through attribute mapping, the connection relationship between network node instances is constructed based on the inter-node communication protocol information, the communication characteristics between network node instances are extracted and the service affinity is calculated, and the initial network topology structure is optimized based on the service affinity to generate a target network topology structure, including:
[0114] Construct a distance matrix based on the Euclidean distance between nodes. Using the graph theory clustering algorithm based on the distance matrix, calculate the local density and relative density of nodes. Combine the requirements of the network node scenario construction to set the density threshold. Normalize the local density and relative density of the nodes to obtain the comprehensive density value of the nodes. Divide the nodes hierarchically according to the requirements of the network topology layer. Determine the topological connection relationship of the nodes in each layer based on the comprehensive density value. Through iterative optimization, obtain the initial network topology structure that meets the hierarchical constraints;
[0115] Extract the hardware configuration information and software configuration information from the target network node template, construct the static attribute feature set and the dynamic attribute feature set. Based on the feature mapping rule, map the static attribute feature set to the hardware parameters of the node instance, and map the dynamic attribute feature set to the software parameters of the node instance to generate the network node instance;
[0116] Design the protocol feature tensor, encode the communication protocol information between node instances as a multi-dimensional feature tensor, use the tensor decomposition method to extract the latent factors of the protocol features, construct a protocol similarity metric model based on the latent factors, calculate the protocol compatibility matrix between node instances, and determine the connection relationship between node instances according to the compatibility threshold;
[0117] Use a sliding time window to extract the time series features of the service traffic between network node instances. Analyze the time series features of the service traffic based on the long short-term memory network to obtain the service traffic prediction result. Construct a service dependency graph through service call chain analysis. Combine the graph attention network to extract the node association features in the service dependency graph. Statistically analyze the node resource utilization features based on the resource monitoring data. Perform multi-dimensional feature fusion on the service traffic prediction result, node association features, and resource utilization features to calculate the service affinity;
[0118] Take the service affinity as the state space and the change of the connection relationship between network node instances as the action space. Construct a reward function considering node processing capacity constraints, link bandwidth constraints, and end-to-end delay constraints. Use the deep reinforcement learning method to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, output the optimal topology connection scheme, and optimize the initial network topology structure through the optimal topology connection scheme to generate the target network topology structure.
[0119] Exemplarily, first, the node distribution density is calculated and the initial topology is constructed. The distance matrix is constructed by calculating the Euclidean distance between each pair of nodes in the network, and the distance values are calculated from the physical location coordinates of the nodes. Taking a network with 100 nodes as an example, each node has three-dimensional coordinate values, and the distances between all node pairs are calculated by traversing. For each node, the number of nodes within its neighborhood range is counted as the local density value, and at the same time, the minimum distance to other high-density nodes is calculated as the relative density value. For example, if the neighborhood radius is set to 10 unit distances, the local density of a certain node being 15 means there are 15 adjacent nodes within this range.
[0120] Next, the node template information is extracted and instances are generated. The node template includes hardware parameters such as the number of CPU cores, memory capacity, and storage space, as well as software parameters such as the operating system type and running environment configuration. For example, a computing node template may include a hardware configuration of 16-core CPU, 64GB memory, and 512GB storage space, as well as a software configuration of Linux operating system and Docker container environment. These parameters are instantiated through the feature mapping rule to generate specific node instances.
[0121] Then, the communication protocol characteristics between nodes are analyzed. Protocol information such as TCP / IP and HTTP is encoded into feature vectors, which include dimensions such as protocol type, port number, and message format. The main features are extracted through feature decomposition to calculate the protocol compatibility between nodes. For example, if two nodes both support the HTTP protocol and the port configurations match, then their protocol compatibility is relatively high.
[0122] Based on the business traffic characteristics, the topology structure is optimized. A 5-minute sliding time window is used to statistically analyze the business traffic between nodes, and historical data is combined to predict the future traffic trend. At the same time, the service call relationship is analyzed to construct a dependency graph. For example, if there are 1000 requests per second on average between nodes A and B and there is a direct service call dependency, it indicates that their business affinity is relatively high.
[0123] Finally, the connection relationship is optimized through deep reinforcement learning. The state space is defined to include the business affinity matrix of nodes, and the action space includes operations such as adding or deleting connections between nodes. The reward function is set considering constraints such as processing capacity, bandwidth, and latency. Through iterative training, the optimal connection strategy is obtained to generate the final network topology structure.
[0124] In this embodiment, through graph theory clustering and multi-level optimization, the automated construction of the network topology structure is achieved, improving the efficiency and accuracy of network planning. The hierarchical method based on node density analysis makes the network structure more reasonable and avoids the problem of unbalanced node distribution. By using feature mapping and protocol compatibility analysis, the feasibility of connections between node instances is ensured, improving the interoperability and reliability of the network. The dynamic attribute mapping mechanism enables the network to have better scalability and adaptability. The optimization method based on service affinity and deep reinforcement learning realizes the dynamic adjustment of the network topology structure, enhancing the network performance and resource utilization rate. Through multi-dimensional feature fusion and consideration of constraint conditions, the practicality and implementability of the optimization results are ensured.
[0125] In an alternative embodiment, a deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithms. When the reward function converges, the output of the optimal topology connection scheme includes:
[0126] Construct a dual-network architecture of a value function network and a policy network. Use temporal difference error to guide the priority sampling of the experience pool and optimize the parameters based on the policy confidence region constraint. At the same time, use the advantage function to adjust the improvement direction of the policy network and introduce the state access distribution to guide the training of the value function network. When the optimization converges, output the sequence with the highest action probability as the optimal topology connection scheme, specifically including:
[0127] Obtain the service affinity matrix and the connection status matrix of the initial network topology structure, and construct a dual-network architecture of a value function network and a policy network. Among them, the value function network extracts state feature vectors based on the service affinity matrix and the connection status matrix and outputs state values; the policy network extracts the correlation features between nodes based on the state feature vectors and outputs the action probability of node connection changes.
[0128] Based on the state value and the reward value calculated based on the node processing capacity constraint, link bandwidth constraint, and end-to-end delay constraint, calculate the temporal difference error. Store the state feature vector, node connection change action probability, reward value, and the state feature vector of the next state as state transition information in the experience pool. Assign sampling priorities to the state transition information in the experience pool based on the temporal difference error, obtain training samples according to the sampling priorities, and use the training samples to update the parameters of the value function network.
[0129] Construct a policy objective function based on the action probability of the node connection relationship change and the state transition information. Use the state value as the baseline function to calculate the policy gradient, and update the parameters of the policy network using the policy gradient and the state transition information under the policy confidence region constraint.
[0130] Taking the temporal difference error as the advantage function, adjusting the improvement direction of the policy network based on the advantage function, generating a state visitation distribution using the node connection change action probabilities output by the policy network, and using the state visitation distribution for the training of the value function network;
[0131] Monitoring the change trends of the reward value, the node connection change action probabilities output by the policy network, and the state values output by the value function network. When the fluctuation amplitude of the change trends is less than the convergence threshold, extracting the action sequence with the highest probability among the node connection change action probabilities output by the policy network as the optimal topology connection scheme.
[0132] Exemplarily, first construct a dual-network architecture system. The value function network adopts a three-layer fully connected neural network structure. The input layer receives the service affinity matrix and the connection status matrix, and extracts features through convolutional operations to obtain the state feature vector. Taking a network with 5 nodes as an example, the service affinity matrix is a 5x5 symmetric matrix, and in the connection status matrix, 1 indicates the existence of a connection between nodes, and 0 indicates the non-existence of a connection. The hidden layer contains 128 neurons, using the ReLU activation function, and the output layer outputs a scalar state value. The policy network also adopts a three-layer structure, sharing the state feature vector as the input, extracting the correlation features between nodes through the graph attention layer, and using the Softmax function in the output layer to obtain the node connection change action probabilities.
[0133] Then perform experience replay training. Calculate the temporal difference error based on the current state value and the reward value calculated considering constraints such as the node CPU utilization rate being less than 80%, the link bandwidth utilization rate being less than 60%, and the end-to-end delay being less than 100 ms. Store the transition information composed of the state feature vector, action probabilities, reward value, and the next state feature vector in an experience pool with a capacity of 10,000. Allocate sampling weights to the samples in the experience pool according to the magnitude of the temporal difference error, and the larger the temporal difference error, the higher the weight. Each time during training, sample 256 samples from the experience pool according to the weights to update the parameters of the value function network.
[0134] Then optimize the policy network. Construct a policy objective function based on the action probabilities and state transition information, and calculate the policy improvement direction using the state value as the baseline function. Under the constraint that the Kullback-Leibler divergence (KL divergence) between the old and new policies is less than 0.01, use the Adam optimizer to update the parameters of the policy network with a learning rate of 0.001. At the same time, take the temporal difference error as the advantage function to adjust the policy network improvement direction, and the action probabilities output by the policy network are used to generate the state visitation distribution to guide the training of the value function network.
[0135] Finally, convergence judgment is carried out. Every 1000 steps of training, calculate the change rates of the average reward value, action probability, and state value in the most recent 100 steps. When the change rates of all three are less than 1%, it is determined that convergence has occurred, and the action sequence with the highest output probability of the policy network is extracted as the optimal solution.
[0136] Figure 3 This is a comparison chart of the link load distribution before and after optimization in the embodiment of the present invention. This chart shows the comparison of the link load distribution before and after network topology optimization. It can be clearly seen from the distribution curve that the link load distribution before optimization (dashed line) presents a "U-shaped" distribution with high values at both ends and low values in the middle, indicating that there are a large number of low-load and high-load links in the network, and the resource utilization is unbalanced. Specific data shows that before optimization, about 15% of the link load rates are lower than 20% (in an idle state), and at the same time, about 12% of the link load rates exceed 80% (in a congested state), and among them, 5% of the link load rates even exceed 95%. After optimization by this technical solution (solid line), the link load distribution presents a more concentrated "bell-shaped" distribution, concentrating on the middle load interval (40%-70%) as a whole. After optimization, the proportion of low-load links (<20%) is reduced to 8%, and the proportion of high-load links (>80%) is reduced to 7%, and no link has a load rate exceeding 90%. Especially in the relatively ideal load interval of 40%-60%, the number of optimized links increases from the original 17 to 24, accounting for 48% of the total number of links. This obvious improvement in load balancing directly reflects that this technical solution can effectively identify congestion points and idle resources in the network, and through intelligent adjustment of the topology connection structure, achieve a more reasonable allocation of network resources, thereby improving the overall network performance and user experience.
[0137] In this embodiment, by constructing a dual-network architecture of a value function network and a policy network, an end-to-end solution to the complex network topology optimization problem is achieved, avoiding the limitations of traditional heuristic algorithms that require manual design of optimization rules. Adopting a training method that combines priority experience replay based on temporal difference error and policy confidence region constraint improves the sample utilization efficiency and ensures stable improvement of the policy, accelerating the algorithm convergence speed. Introducing a two-way guidance mechanism of the advantage function and the state access distribution realizes the collaborative optimization of value function estimation and policy improvement, improving the algorithm performance and ensuring the reliability of the output topology solution.
[0138] In an alternative embodiment, a resource utilization rate metric is generated according to the target network topology structure. A node operating environment is constructed and network services are deployed based on a resource optimization plan obtained by predicting the resource utilization rate metric. A stress test is performed on the network services to generate a fault feature sequence. A matching vulnerability program is selected from a preset vulnerability program library based on the fault feature sequence and implanted into the node operating environment. The status information in the node operating environment is monitored and anomaly detection and repair are performed according to the fault feature sequence, generating a large-scale network node scenario that meets the constraints of the resource optimization plan, including:
[0139] Construct a multi-dimensional resource state space, map the CPU state vector, memory state vector, network state vector, and disk state vector of network nodes in the target network topology structure to the multi-dimensional resource state space, perform adversarial training on the state vectors using an adversarial variational autoencoder to obtain a resource state distribution, calculate the resource state entropy based on the resource state distribution, construct a loss function for the resource prediction model, and train a recurrent neural network using the loss function to obtain a resource utilization rate prediction model. Input the historical resource state distribution into the resource utilization rate prediction model to generate future resource utilization rate metrics, and set resource allocation parameters based on the resource utilization rate metrics to generate a resource optimization plan;
[0140] Calculate the system stability matrix based on the resource state entropy, perform singular value decomposition on the stability matrix to obtain a characteristic mode sequence, identify system state mutation points based on the characteristic mode sequence, use the system state mutation points as fault injection times, and construct a node operating environment and deploy network services at the fault injection times according to the resource optimization plan;
[0141] Perform a stress test on the network services to collect system state data, map the system state data to a feature manifold using a complex variable kernel function, calculate the geodesic on the feature manifold to obtain a fault propagation path, calculate curvature features based on the fault propagation path to construct a fault feature sequence, perform manifold matching between the fault feature sequence and the vulnerability features in the preset vulnerability program library, and select the vulnerability program with the highest matching degree and meeting the constraints of the resource optimization plan and implant it into the node operating environment;
[0142] Analyze the feature manifold using the persistent homology method to obtain the fault persistence degree, construct a repair threshold based on the coupling relationship between the resource state entropy and the fault persistence degree, perform anomaly detection and repair on the node operating environment according to the repair threshold, and when the resource utilization rate metric of the repaired node operating environment meets the constraints of the resource optimization plan, output the current node operating environment as a large-scale network node scenario.
[0143] A method for constructing a large-scale network node scenario, which can simulate a real network environment for testing and verifying the stability and reliability of network services. The core of this method is to optimize resource allocation according to the target network topology structure and the predicted results of resource utilization, and simulate failures and perform repairs on nodes.
[0144] Exemplarily, first, collect the target network topology structure information, including the number of nodes, connection relationships, and the hardware configuration of each node, such as the number of CPU cores, memory size, network bandwidth, and disk capacity. Then, collect the status information of network nodes, such as CPU usage, memory usage, network traffic, and disk I / O, and convert this information into a multi-dimensional vector representation, such as a CPU status vector, a memory status vector, a network status vector, and a disk status vector.
[0145] Next, use an adversarial variational autoencoder to train these status vectors. The adversarial variational autoencoder consists of an encoder and a decoder. The encoder compresses the high-dimensional status vector into a low-dimensional representation, and the decoder attempts to reconstruct the original status vector from the low-dimensional representation. Through adversarial training, the encoder can extract the key features in the status vector and learn the probability distribution of the resource status.
[0146] Based on the learned resource status distribution, calculate the resource status entropy, which reflects the degree of chaos of the resource status. The higher the entropy value, the more unstable the resource status. Use the resource status entropy to construct the loss function of the resource prediction model, and use this loss function to train a recurrent neural network, such as a long short-term memory network (LSTM), to predict the resource utilization in the future for a period of time. Input the historical resource status distribution into the trained recurrent neural network to obtain the future resource utilization metrics, such as the CPU usage and memory usage of each node in the future for a period of time.
[0147] According to the predicted resource utilization metrics, formulate a resource optimization plan, such as determining the CPU allocation quota and memory allocation quota for each node. Then, calculate the system stability matrix based on the resource status entropy, which reflects the stability degree of the system in different resource states. Perform singular value decomposition on the stability matrix to obtain the eigenmode sequence, which reflects the change trend of the system state over time. By analyzing the eigenmode sequence, identify the system state mutation points, that is, the moments when the system stability changes significantly. Use these mutation points as the fault injection moments.
[0148] At the preset fault injection moment, construct the node running environment according to the resource optimization plan, and deploy network services on the nodes. Then, perform stress tests on the deployed network services, such as simulating a large number of users accessing the service simultaneously, and collect system status data, such as CPU usage, memory usage, network latency, etc. Use the complex variable kernel function to map the collected system status data to a high-dimensional feature manifold, and calculate the geodesic on this manifold to obtain the fault propagation path. Calculate the curvature features based on the fault propagation path to construct a fault feature sequence, which describes the feature changes during the fault propagation process.
[0149] Perform manifold matching between the generated fault feature sequence and the vulnerability features in the preset vulnerability program library, select the vulnerability program with the highest matching degree and meeting the constraints of the resource optimization plan, and implant it into the node running environment. The preset vulnerability program library contains various types of vulnerability programs, such as buffer overflow vulnerabilities, SQL injection vulnerabilities, etc., and each vulnerability program has a corresponding feature description.
[0150] Adopt the persistent homology method to analyze the feature manifold to obtain the fault persistence, which reflects the duration of the fault. Based on the coupling relationship between the resource state entropy and the fault persistence, construct a repair threshold. When the system state entropy and the fault persistence exceed the repair threshold, it is considered that the system needs to be repaired. Perform anomaly detection and repair on the node running environment according to the repair threshold, such as restarting services, updating patches, etc. When the resource utilization index of the repaired node running environment meets the constraints of the resource optimization plan, output the current node running environment as a large-scale network node scenario.
[0151] For example, in a network with 10 nodes, a resource state vector was constructed by collecting the CPU usage and memory usage of the nodes. After training with an adversarial variational autoencoder, the resource state distribution was obtained. Use this distribution to calculate the resource state entropy, and train a recurrent neural network to predict the resource utilization in the next 24 hours. According to the prediction results, the CPU allocation quota for each node was set to 80%, and the memory allocation quota was set to 70%. When simulating fault injection, a buffer overflow vulnerability program was selected and implanted into node 3. After anomaly detection and repair, the CPU usage and memory usage of node 3 returned to normal levels and met the constraints of the resource optimization plan.
[0152] In this embodiment, by constructing a multi-dimensional resource state space, the CPU, memory, network, and disk resource states of network nodes are accurately characterized, and an adversarial variational autoencoder is used for training to make the resource state distribution more realistic and improve the accuracy of resource utilization prediction. Based on the prediction model, future resource utilization indicators are generated to optimize the resource allocation scheme, thereby enhancing the overall resource management efficiency of the system. By calculating the resource state entropy and combining the singular value decomposition method, the system state mutation points can be effectively identified, and the fault injection moment can be accurately determined, making the fault simulation more realistic. The system state data is mapped to a feature manifold using a complex variable kernel function, and the geodesic is calculated to analyze the fault propagation path, making the fault feature extraction more accurate. Combining the fault feature manifold matching method, the vulnerability program that best meets the resource optimization constraints can be screened from the preset vulnerability program library, improving the pertinence and effectiveness of vulnerability testing. The persistent homology analysis method is used to calculate the fault duration, and a repair threshold is constructed in combination with the resource state entropy to achieve intelligent anomaly detection and repair of the node operating environment, ensuring that the repaired environment can meet the constraints of the resource optimization scheme. Finally, this scheme can construct a large-scale network node scenario that meets the resource optimization requirements, improving the authenticity, stability, and efficiency of network simulation and attack and defense testing, and providing strong support for network security research and infrastructure optimization.
[0153] In an alternative embodiment, the persistent homology method is used to analyze the feature manifold to obtain the fault duration, and constructing a repair threshold based on the coupling relationship between the resource state entropy and the fault duration includes:
[0154] Constructing a nested sequence of simplicial complexes on the feature manifold, using the homology group mapping to extract the duration information of the fault features, combining two-level feature weights optimization to obtain a corrected fault duration, establishing a coupling matrix between the fault duration and the resource state entropy, and performing eigenvalue decomposition on the coupling matrix to obtain the repair threshold, specifically including:
[0155] Constructing a distance metric space on the feature manifold, calculating the distance values between point pairs based on the distance metric space, constructing a simplicial complex using the distance values, generating a nested sequence of the simplicial complexes by gradually increasing the distance values, calculating the homology group mapping between adjacent simplicial complexes in the nested sequence to obtain a topological feature sequence, extracting the appearance time and disappearance time of the features in the topological feature sequence, calculating the feature duration based on the appearance time and disappearance time, and summing the weighted feature durations to obtain the fault duration;
[0156] Assigning a weighting coefficient to the fault duration according to the structure of the simplicial complex, taking the product of the weighting coefficient and the fault duration as the dimension feature value, performing eigenvalue decomposition on the dimension feature value to obtain the feature weight, and summing the products of the feature weight and the dimension feature value to obtain the corrected fault duration;
[0157] Calculate the correlation coefficient between the corrected fault duration and the resource state entropy, fill the correlation coefficient into the diagonal matrix composed of the corrected fault duration and the resource state entropy to obtain the coupling matrix, perform eigen decomposition on the coupling matrix to obtain the eigenvector, multiply the eigenvector by the corrected fault duration and the resource state entropy respectively and sum to obtain the threshold decision value, and optimize the threshold decision value with the marked repair decision data to obtain the repair threshold.
[0158] Exemplarily, first, construct a nested sequence of simplicial complexes on the feature manifold. The feature manifold is a topological representation of the system state, which is a geometric structure in a high-dimensional space, and each point represents the resource state of the system at a certain moment, including CPU load, memory occupancy, network bandwidth usage, and disk I / O status, etc. The manifold can capture the continuous changes of the system state and is suitable for analyzing the fault propagation mode. A simplicial complex is a topological structure composed of multiple simplices (such as points, line segments, triangles, and their high-dimensional generalizations) and is used to represent the topological connection relationship between data points. To construct a simplicial complex on the manifold, first, a distance metric space needs to be defined to calculate the similarity between data points. The calculation of the distance metric space can use methods such as Euclidean distance, Mahalanobis distance, or cosine similarity to measure the differences between different resource state vectors.
[0159] After constructing the distance metric space, the distance values between point pairs need to be calculated. The distance value is used to judge the similarity between two data points (i.e., resource states). When the distance is less than the set threshold, a topological connection is established between them to form a simplex. As the distance threshold gradually increases, the structure of the simplicial complex will gradually change, thus forming a nested sequence, that is, the topological structure at different scales. The construction of the nested sequence can be achieved by methods such as Vietoris-Rips complex (VR complex), which can gradually connect data points at different scales and generate hierarchical changes in the topological structure.
[0160] After constructing the nested sequence, the homology group mapping needs to be used to analyze the topological feature changes at different scales. The homology group is a topological invariant that can characterize features such as connected components, loop structures, and holes in the data topological structure. For example, at a small scale, different resource states may be independent of each other, but as the scale increases, some states will gradually merge, and this change can be reflected by the homology group mapping. The homology group mapping is used to analyze the topological feature changes between adjacent simplicial complexes and generate a topological feature sequence, which includes the appearance time and disappearance time of each topological feature.
[0161] Based on the emergence time and disappearance time, the feature duration can be calculated, which is the existence time of a certain topological feature at different scales. Features with longer durations usually represent stable topological structures, such as some long-term existing resource state patterns of the system; while features with shorter durations may represent instantaneous anomalies, such as sudden spikes in CPU load or network congestion. Therefore, calculating the duration of topological features and performing a weighted sum on them can obtain a preliminary fault duration measure, which is used to measure the stability and impact scope of system faults.
[0162] To optimize the fault duration measure, it is necessary to perform weighted processing in combination with the structural features of the simplicial complex. The structural features of the simplicial complex include topological connectivity, local density, dimension information, etc. By calculating the local connectivity of each simplex, its importance in the entire topological structure is determined, and a weighted coefficient is assigned to it. Multiplying these weighted coefficients by the fault duration measure values can obtain the dimensional feature values of each dimension. Then, performing eigen-decomposition on these dimensional feature values to calculate the eigen-weights of different dimensions, and finally obtaining the corrected fault duration measure to improve the accuracy and robustness of fault analysis.
[0163] Next, calculate the coupling relationship between the corrected fault duration measure and the resource state entropy, and then construct a coupling matrix. The resource state entropy is used to measure the balance degree of system resources. It is based on the concept of information entropy and evaluates the stability of the system by calculating the distribution of resource states such as CPU, memory, network, and disk. A higher entropy value indicates that the resource usage is relatively uniform and the system is more stable, while a lower entropy value indicates that there are anomalies in some resources, such as too high CPU occupancy or a bottleneck in a certain network port.
[0164] To establish the relationship between the fault duration measure and the resource state entropy, first, it is necessary to calculate their correlation coefficients to measure the coupling degree between these two variables. Then, fill the correlation coefficients into the diagonal matrix composed of the corrected fault duration measure and the resource state entropy to generate a coupling matrix. The coupling matrix is used to describe the global correlation between the system resource state and the fault persistence.
[0165] After the coupling matrix is constructed, eigen-decomposition needs to be performed to extract the key eigenvectors. These eigenvectors are used to identify the main factors affecting system stability. For example, some resource state patterns may lead to specific types of faults. Based on the eigenvectors, a threshold decision value can be calculated to measure whether the system is in an acceptable operating state. The specific calculation method is to multiply the eigenvectors by the corrected fault duration measure and the resource state entropy respectively and sum them to obtain a global threshold index.
[0166] To optimize the threshold determination result, historical repair decision data needs to be utilized for adjustment. The historical repair decision data includes information such as past system failures, the scope of failure impact, the repair measures taken and their effectiveness, etc. Through machine learning methods, such as those based on gradient boosting decision trees or Bayesian optimization, the parameters of the threshold calculation model can be adjusted to better conform to the actual system operation conditions. The optimized repair threshold can more accurately judge the system's fault recovery ability under different resource states and be used to guide the execution of the automated repair strategy.
[0167] Table 1 is a comparison table of the comprehensive performance indicators of different fault analysis methods in the embodiments of the present invention, which comprehensively compares the performance of this technical solution with other methods in multiple performance indicators. The accuracy rate of fault detection of this technical solution reaches 94.6%, significantly higher than other methods, while maintaining the lowest false alarm rate (3.2%) and missed alarm rate (2.2%). In terms of processing time, although the traditional statistical method is faster (0.57 ms / sample), this technical solution (0.98 ms / sample) has obvious advantages compared with the deep learning method (2.86 ms / sample) and classical coherence analysis (1.74 ms / sample). In terms of resource consumption, this technical solution (245 MB) is much lower than the deep learning method (876 MB), saving about 40% of the resources compared with classical coherence analysis (412 MB).
[0168] Table 1 Comparison table of comprehensive performance indicators of different fault analysis methods;
[0169]
[0170] In this embodiment, by constructing a feature manifold and using simplicial complexes to analyze the system state, the topological relationship between different resource states can be accurately captured, improving the accuracy of fault detection. Using homology group mapping to analyze the change of topological features enables the calculation of fault duration to reflect the scope of fault impact of the system at different scales, improving the anomaly detection ability. By calculating the resource state entropy and performing coupled analysis with the fault duration, the overall stability of the system can be better measured, thereby realizing refined resource management and fault prediction. By optimizing the repair threshold through feature decomposition and dynamically adjusting it in combination with historical repair decision data, the repair threshold is more in line with the actual application scenario, thereby improving the effectiveness and adaptability of the automated repair strategy.
[0171] The second aspect of the embodiments of the present invention
[0172] provides a large-scale network node scenario construction system based on a network range, and the system includes:
[0173] The first unit is used to calculate the vulnerability correlation degree between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate a distribution map of attack and defense level nodes, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the distribution map of attack and defense level nodes, and screen out the target network node templates;
[0174] The second unit is used to calculate the node distribution density threshold by using the graph theory clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain the initial network topology structure, generate network node instances by attribute mapping of the target network node templates, construct the connection relationship between network node instances based on the inter-node communication protocol information, extract the communication characteristics between network node instances and calculate the service affinity, and optimize the initial network topology structure based on the service affinity to generate the target network topology structure;
[0175] The third unit is used to generate resource utilization indicators according to the target network topology structure, construct the node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate a fault feature sequence, select a matching vulnerability program from the preset vulnerability program library based on the fault feature sequence and implant it into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.
[0176] In the third aspect of the embodiments of the present invention,
[0177] A kind of electronic device is provided, including:
[0178] A processor;
[0179] A memory for storing instructions executable by the processor;
[0180] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0181] In the fourth aspect of the embodiments of the present invention,
[0182] A computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0183] The present invention can be a method, device, system and / or computer program product. The computer program product can include a computer-readable storage medium, on which computer-readable program instructions for executing various aspects of the present invention are uploaded.
[0184] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A large-scale network node scenario construction method based on a network range, characterized in that: include: Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; A graph clustering algorithm is used to calculate the node distribution density threshold and hierarchically optimize the network topology type in the network node scenario construction requirements to obtain the initial network topology structure. The target network node template is used to generate a network node instance through attribute mapping. The connection relationship between network node instances is constructed based on the communication protocol information between nodes. The communication characteristics between network node instances are extracted and the business affinity is calculated. The initial network topology structure is optimized based on the business affinity to generate the target network topology structure. Generate resource utilization indicators according to the target network topology structure, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from a preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequences, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan; Calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node templates including: According to the vulnerability correlation between nodes, a node correlation graph is constructed. The node correlation graph is divided based on the community discovery algorithm to generate an attack and defense level node distribution graph. The vulnerability exploitation chain is introduced and the trigger probability of adjacent vulnerabilities and the attack chain length attenuation coefficient are calculated. The vulnerability intensity values at the corresponding positions in the attack and defense level node distribution graph are matched. The candidate network node template with the minimum matching value is selected as the target network node template. Specifically, it includes: Obtain vulnerability attribute information of network nodes to generate node vulnerability feature vectors, calculate distance decay function values based on the number of communication hops between nodes, perform tensor operations on the node vulnerability feature vectors and the distance decay function values to obtain node vulnerability combination matrices, and calculate vulnerability correlations between nodes in network node scenario construction requirements based on the node vulnerability combination matrix; The vulnerability correlation degree is used as the edge weight to construct a node correlation graph, the node correlation graph is iteratively divided using a community discovery algorithm, the network nodes are divided into multiple attack and defense levels, and the level vulnerability strength value is calculated for each attack and defense level; Generate an attack and defense level node distribution graph based on the level position relationship of the attack and defense levels and the level vulnerability strength values, wherein the nodes represent the attack and defense levels, and the connecting edges between the nodes represent the vulnerability strength relationship between the levels; Extract candidate network node templates from a preset network node template library, establish connection relationships between vulnerabilities based on vulnerability features in the candidate network node templates through system state requirements, state changes, and attack entry types in the vulnerability features, introduce system state change continuity as a screening condition for vulnerability exploitation chains, and combine the cascade trigger probability of the attack chain with the length attenuation coefficient to calculate the vulnerability chain propagation coefficient; The vulnerability chain propagation coefficient is matched and calculated with the vulnerability strength value of the corresponding position in the attack and defense hierarchical node distribution map to obtain a propagation coefficient deviation value, and the hierarchical vulnerability strength change amount after deployment is calculated based on the candidate network node template. The weighted sum of the propagation coefficient deviation value and the hierarchical vulnerability strength change amount is determined as a matching value, and the candidate network node template with the minimum matching value is selected as the target network node template; The connection relationship between vulnerabilities is established through the system state requirements, state changes and attack entry types in the vulnerability characteristics. The continuity of system state changes is introduced as the screening condition for the vulnerability exploit chain. The cascade trigger probability of the attack chain is combined with the length attenuation coefficient. The vulnerability chain propagation coefficient is calculated, including: Extract vulnerability features from the candidate network node template, wherein the vulnerability features include system state requirements triggered by the vulnerability, system state changes after the vulnerability is exploited, and attack entry types of the vulnerability exploitation, and construct a vulnerability feature vector; Perform feature matching according to the system state requirements, system state changes, and attack entry types in the vulnerability feature vector, and establish a connection relationship between the two vulnerabilities when the system state change of the first vulnerability meets the system state requirements of the second vulnerability and the attack entry type of the second vulnerability belongs to the attack entry introduced by the first vulnerability; Building a vulnerability dependency graph based on the connection relationship, identifying a vulnerability exploit chain path in the vulnerability dependency graph using a depth-first search method, screening the vulnerability exploit chain path according to the continuity of system state changes in the vulnerability feature vector, and generating a vulnerability exploit chain; Based on the number of nodes in the vulnerability exploit chain, the connection distance between adjacent nodes is calculated, the path length of the vulnerability exploit chain is calculated according to the connection distance, and the path length is substituted into an exponential decay function to obtain an attack chain length decay coefficient of the vulnerability exploit chain; For adjacent vulnerabilities in the vulnerability exploitation chain, the triggering probabilities of the adjacent vulnerabilities are multiplied in sequence according to the connection order of the vulnerabilities in the vulnerability exploitation chain to obtain the cascade triggering probability of the vulnerability exploitation chain, and the cascade triggering probability is multiplied by the attack chain length attenuation coefficient to obtain the vulnerability chain propagation coefficient; An attack path graph is constructed based on the vulnerability feature vector and the vulnerability exploitation chain, and the vulnerability exploitation chain is mapped to an attack path. The number of successes of the attack path is counted through multiple simulations, and the calculation parameters of the trigger probability and the attack chain length attenuation coefficient are optimized using the number of successes of the attack path. The vulnerability chain propagation coefficient is recalculated using the optimized parameters to obtain the final vulnerability chain propagation coefficient.
2. The method according to claim 1, characterized in that The graph clustering algorithm is used to calculate the node distribution density threshold and the network topology type in the network node scenario construction requirements is hierarchically optimized to obtain the initial network topology structure. The target network node template is used to generate a network node instance through attribute mapping. The connection relationship between network node instances is constructed based on the communication protocol information between nodes. The communication characteristics between network node instances are extracted and the business affinity is calculated. The initial network topology structure is optimized based on the business affinity. The target network topology structure is generated, including: A distance matrix is constructed according to the Euclidean distance between nodes. A graph clustering algorithm is used based on the distance matrix to calculate the local density and relative density of nodes. A density threshold is set in combination with the network node scenario construction requirements. The local density and relative density of the nodes are normalized to obtain the node comprehensive density value. The nodes are hierarchically divided according to the network topology layering requirements. The topological connection relationship of the nodes in each layer is determined according to the comprehensive density value. The initial network topology structure that meets the hierarchical constraints is obtained through iterative optimization. Extracting hardware configuration information and software configuration information from the target network node template, constructing a static attribute feature set and a dynamic attribute feature set, mapping the static attribute feature set to the hardware parameters of the node instance based on the feature mapping rule, mapping the dynamic attribute feature set to the software parameters of the node instance, and generating a network node instance; Design a protocol feature tensor, encode the communication protocol information between node instances into a multi-dimensional feature tensor, use a tensor decomposition method to extract implicit factors of the protocol features, build a protocol similarity measurement model based on the implicit factors, calculate the protocol compatibility matrix between node instances, and determine the connection relationship between node instances according to the compatibility threshold; A sliding time window is used to extract the business traffic time series characteristics between network node instances. The business traffic time series characteristics are analyzed based on the long short-term memory network to obtain the business traffic prediction results. A business dependency graph is constructed through service call chain analysis. The node association characteristics in the business dependency graph are extracted in combination with the graph attention network. The node resource utilization characteristics are counted based on resource monitoring data. The business traffic prediction results, node association characteristics and resource utilization characteristics are fused in multiple dimensions to calculate the business affinity. Taking business affinity as the state space and the change of connection relationship between network node instances as the action space, a reward function that considers node processing capacity constraints, link bandwidth constraints and end-to-end delay constraints is constructed. The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topology connection plan is output. The initial network topology structure is optimized through the optimal topology connection plan to generate the target network topology structure.
3. The method according to claim 2, characterized in that The deep reinforcement learning method is used to iteratively optimize the connection strategy based on value function estimation and policy gradient algorithm. When the reward function converges, the optimal topological connection solution is output, including: A dual network architecture of value function network and policy network is constructed. The temporal difference error is used to guide the priority sampling of the experience pool and the parameters are optimized based on the policy trust region constraint. At the same time, the advantage function is used to adjust the improvement direction of the policy network and the state access distribution is introduced to guide the training of the value function network. When the optimization converges, the sequence with the highest action probability is output as the optimal topological connection solution, which includes: Obtaining the business affinity matrix and the connection state matrix of the initial network topology structure, and constructing a dual network architecture of a value function network and a policy network, wherein the value function network extracts features based on the business affinity matrix and the connection state matrix to obtain a state feature vector, and outputs a state value; the policy network extracts node association features based on the state feature vector, and outputs a node connection change action probability; Based on the state value and the reward value calculated based on the node processing capacity constraint, the link bandwidth constraint and the end-to-end delay constraint, a time difference error is calculated, the state feature vector, the node connection change action probability, the reward value and the state feature vector of the next state are stored in an experience pool as state transition information, a sampling priority is assigned to the state transition information in the experience pool based on the time difference error, training samples are obtained according to the sampling priority, and the parameters of the value function network are updated using the training samples; Constructing a policy objective function based on the action probability and state transition information of the node connection relationship change, calculating the policy gradient using the state value as a baseline function, and updating the parameters of the policy network using the policy gradient and state transition information under the policy trust region constraint; Using the temporal difference error as an advantage function, adjusting the improvement direction of the policy network based on the advantage function, generating a state access distribution using the node connection change action probability output by the policy network, and using the state access distribution for training the value function network; Monitor the changing trends of the reward value, the node connection change action probability output by the policy network, and the state value output by the value function network. When the fluctuation amplitude of the changing trend is less than the convergence threshold, extract the action sequence with the highest probability in the node connection change action probability output by the policy network as the optimal topological connection plan.
4. The method according to claim 1, characterized in that Generate resource utilization indicators based on the target network topology, build a node operating environment and deploy network services through the resource optimization solution obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate fault feature sequences, select matching vulnerability programs from the preset vulnerability program library based on the fault feature sequences and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair based on the fault feature sequences, and generate large-scale network node scenarios that meet the constraints of the resource optimization solution, including: Construct a multidimensional resource state space, map the CPU state vector, memory state vector, network state vector and disk state vector of the network node in the target network topology structure to the multidimensional resource state space, use an adversarial variational autoencoder to perform adversarial training on the state vector to obtain a resource state distribution, calculate the resource state entropy based on the resource state distribution, construct a loss function of the resource prediction model, use the loss function to train a recurrent neural network to obtain a resource utilization prediction model, input the historical resource state distribution into the resource utilization prediction model to generate a future resource utilization index, and set resource allocation parameters based on the resource utilization index to generate a resource optimization plan; Calculating a system stability matrix based on the resource state entropy, performing singular value decomposition on the stability matrix to obtain a characteristic mode sequence, identifying a system state mutation point based on the characteristic mode sequence, taking the system state mutation point as a fault injection moment, and constructing a node operating environment and deploying network services at the fault injection moment according to the resource optimization solution; Performing stress testing on the network service to collect system status data, mapping the system status data to a characteristic manifold using a complex variable kernel function, calculating geodesics on the characteristic manifold to obtain a fault propagation path, constructing a fault feature sequence based on the curvature characteristics of the fault propagation path, performing manifold matching on the fault feature sequence and the vulnerability features in a preset vulnerability program library, and selecting a vulnerability program with the highest matching degree and satisfying the constraints of the resource optimization solution to be implanted into the node operating environment; The characteristic manifold is analyzed by a continuous coherence method to obtain the fault duration, a repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, anomaly detection and repair of the node operating environment are performed according to the repair threshold, and when the resource utilization index of the repaired node operating environment meets the constraints of the resource optimization solution, the current node operating environment is output as a large-scale network node scenario.
5. The method according to claim 4, characterized in that The characteristic manifold is analyzed by the continuous coherence method to obtain the fault duration, and the repair threshold is constructed based on the coupling relationship between the resource state entropy and the fault duration, including: A nested sequence of simplex complexes is constructed on the feature manifold. The duration information of the fault feature is extracted using homology group mapping. The corrected fault duration is obtained by combining two-level feature weight optimization. The coupling matrix of fault duration and resource state entropy is established. The coupling matrix is decomposed by features to obtain the repair threshold, which includes: Constructing a distance metric space on a characteristic manifold, calculating the distance value between point pairs based on the distance metric space, constructing a simplex complex using the distance value, generating a nested sequence of the simplex complex by gradually increasing the distance value, calculating the homology group mapping between adjacent simplex complexes in the nested sequence to obtain a topological characteristic sequence, extracting the appearance time and disappearance time of features in the topological characteristic sequence, calculating the feature duration based on the appearance time and disappearance time, and obtaining the fault duration by weighted summation of the feature duration; According to the structure of the simplex complex, a weight coefficient is assigned to the fault duration, the product of the weight coefficient and the fault duration is used as a dimensional eigenvalue, the dimensional eigenvalue is subjected to eigendecomposition to obtain a feature weight, and the product of the feature weight and the dimensional eigenvalue is summed to obtain a corrected fault duration; Calculate the correlation coefficient between the corrected fault duration and resource state entropy, fill the correlation coefficient into the diagonal matrix composed of the corrected fault duration and resource state entropy to obtain a coupling matrix, perform eigendecomposition on the coupling matrix to obtain eigenvectors, multiply the eigenvectors with the corrected fault duration and resource state entropy respectively and sum them to obtain a threshold judgment value, and use the threshold judgment value and the marked repair decision data to optimize to obtain a repair threshold.
6. A large-scale network node scenario construction system based on a network range, used to implement the method described in any one of claims 1 to 5, characterized in that: include: The first unit is used to calculate the vulnerability correlation between nodes in the network node scenario construction requirements, divide the network nodes into multiple attack and defense levels, generate an attack and defense level node distribution map, extract candidate network node templates from the network node template library and calculate the vulnerability chain propagation coefficient, match the vulnerability chain propagation coefficient with the attack and defense level node distribution map, and screen out the target network node template; The second unit is used to calculate the node distribution density threshold using a graph clustering algorithm and perform hierarchical optimization on the network topology type in the network node scenario construction requirements to obtain an initial network topology structure, generate a network node instance from a target network node template through attribute mapping, build a connection relationship between network node instances based on inter-node communication protocol information, extract communication features between network node instances and calculate service affinity, optimize the initial network topology structure based on service affinity, and generate a target network topology structure; The third unit is used to generate resource utilization indicators according to the target network topology, build a node operating environment and deploy network services through the resource optimization plan obtained by predicting the resource utilization indicators, perform stress testing on the network services to generate a fault feature sequence, select matching vulnerability programs from a preset vulnerability program library based on the fault feature sequence and implant them into the node operating environment, monitor the status information in the node operating environment and perform anomaly detection and repair according to the fault feature sequence, and generate a large-scale network node scenario that meets the constraints of the resource optimization plan.
7. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method described in any one of claims 1 to 5.
8. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Selectively Choosing Between Actual-Attack and Simulation / Evaluation for Validating a Vulnerability of a Network Node During Execution of a Penetration Testing Campaign
US20190149572A1
A smart password implementation method, apparatus, electronic device and computer-readable medium
US20240031356A1