SDN-based large-scale host vulnerability identification and attack response simulation method
By using Mininet and JSON formats to configure vulnerability properties in the SDN environment, combined with the real-time monitoring and response mechanism of the SDN controller, the shortcomings of host-level vulnerability simulation in the existing technology are solved, and efficient simulation and authenticity improvement of large-scale networks are achieved.
Patent Information
- Application Number
- CN202510357755.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-03-25
AI Technical Summary
The existing network security and attack response simulation technologies lack precise description and dynamic simulation of vulnerabilities at the host level, making it difficult to adapt to the complexity and dynamic nature of large-scale networks, resulting in insufficient scalability and poor authenticity.
Using large-scale host vulnerability identification and attack response simulation methods based on SDN, a network topology is created through Mininet scripts, vulnerability properties are configured for the host using JSON format, and network traffic and host status are monitored in real time through the SDN controller, abnormal behavior is identified and response mechanisms are triggered.
It realizes accurate reproduction and dynamic simulation of complex vulnerabilities, improves the simulation capabilities of the network security simulation environment for real attack scenarios, supports large-scale network simulation and maintains high efficiency and scalability.
Smart Images

Figure CN120017408A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a large-scale host vulnerability identification and attack response simulation method based on SDN. Background Art
[0002] Existing network security and attack response simulation technologies mainly focus on network-level traffic management, routing optimization, and rule-based security protection strategies. In traditional methods, simulation platforms usually simulate attacker behavior and test the network's defense capabilities through predefined network topologies and traffic patterns combined with static protection rules. For example, hard-coded rules are used to control the transmission path of data packets, or traffic generation tools (such as iperf) are used to simulate scenarios such as denial of service attacks. In addition, some methods combine software-defined networking (SDN) technology to manage network traffic through centralized controllers and support dynamic configuration of switches and routers to enhance the network's monitoring and scheduling capabilities. These technologies have been widely used in small and medium-sized network environments and can achieve basic attack simulation and response testing.
[0003] However, the limitation of existing technologies is that they pay less attention to the security attribute identification at the host level, especially the accurate description and dynamic simulation of vulnerabilities. Traditional simulation methods usually rely on simplified attack models and static rules, and cannot accurately reflect the multi-dimensional characteristics of complex vulnerabilities (such as vulnerability types, impact ranges, and exploitability in CVE descriptions), resulting in a large gap between attack simulation and real-world scenarios. For example, when simulating attacks against specific CVE vulnerabilities, traditional methods find it difficult to adjust attack paths or strategies based on the specific security attributes of the host, limiting in-depth analysis of the vulnerability exploitation process. In addition, traditional simulation platforms mostly use fixed network topologies and traffic patterns, which are difficult to adapt to the complexity and dynamics of large-scale networks (such as hundreds or thousands of nodes). As the number of nodes increases, the accuracy of their management and simulation decreases significantly. This makes existing methods exhibit the disadvantages of insufficient scalability and poor authenticity when dealing with host vulnerability identification, attack response, and resource scheduling issues in large-scale networks. Summary of the invention
[0004] In order to remedy the above shortcomings, the present invention provides a large-scale host vulnerability identification and attack response simulation method based on SDN, aiming to improve the problem that traditional simulation methods usually rely on simplified attack models and static rules and cannot accurately reflect the multi-dimensional characteristics of complex vulnerabilities.
[0005] In a first aspect, the present invention provides the following technical solution, a large-scale host vulnerability identification and attack response simulation method based on SDN, comprising the following steps:
[0006] Step 1: Create a network topology using the Mininet script. The network topology includes hosts, switches, and controllers. The SDN controller is used to centrally manage traffic and node status in the network topology. The network performance in the actual scenario is simulated by setting the topology type, bandwidth, and delay parameters.
[0007] Step 2: In the SDN network environment, vulnerability attributes are configured for the host in JSON format. The vulnerability attributes include vulnerability number, hazard level, impact range, and repair suggestions. The host vulnerability attributes can be quickly edited and batch assigned through scripts to achieve automated vulnerability identification, so as to generate a topology node that identifies the vulnerability information.
[0008] Step 3: Based on the host vulnerability identification, select the corresponding attack strategy and execute the simulated attack. Monitor the network traffic and host status in real time through the SDN controller, identify abnormal behavior and trigger the response mechanism. The response mechanism includes traffic restriction, host isolation and data flow rerouting based on OpenFlow rules to simulate the defense mechanism in network attacks.
[0009] Preferably, the network topology created in step 1 supports tree, grid or ring topology types, the SDN controller communicates with the switch via the OpenFlow protocol to perform flexible scheduling and real-time monitoring of network traffic, the method is applied to large-scale network environments, supports simulation of hundreds to thousands of host nodes, and improves simulation efficiency and system scalability through centralized management.
[0010] Preferably, the JSON format vulnerability attributes in step 2 also include vulnerability type, affected software version and attack conditions. The SDN controller parses the JSON vulnerability attributes of the host node through a vulnerability scanning module, extracts vulnerability feature information, and formulates an attack plan based on the vulnerability feature information. The attack plan includes target host selection and attack method determination.
[0011] Preferably, the attack strategy in step 3 includes one or more of exploitation attacks and denial of service attacks against host vulnerabilities, and each attack type supports configuration of different attack strengths, frequencies, and durations; after identifying abnormal behavior, the SDN controller automatically adjusts network traffic according to a preset defense strategy, and the defense strategy includes enabling traffic filtering, adding firewall rules, or activating an intrusion detection and prevention system to mitigate the impact of attacks and ensure network security.
[0012] Preferably, the SDN controller interacts with the host in real time. After detecting a host vulnerability, the SDN controller pushes vulnerability repair suggestions to the affected host and generates a repair strategy in collaboration with an external vulnerability management system. Through traffic scheduling and policy adjustment, the load of the attacked host is reduced, and detailed vulnerability and attack logs are generated, including vulnerability identification information, attack behavior records, and response measures to support subsequent analysis and optimization.
[0013] Preferably, the external interface module is also supported to connect with the external vulnerability database to automatically synchronize vulnerability information, dynamically configure host vulnerability attributes and monitor simulation effects in real time through a graphical interface.
[0014] Preferably, the SDN controller dynamically adjusts the network's resource allocation strategy by monitoring network traffic and attack characteristics in real time, including adjusting traffic routing and limiting resource access of affected hosts, so as to simulate a real attack response process and prevent the continued impact of the attack.
[0015] In a second aspect, the present invention provides the following technical solution, a large-scale host vulnerability identification and attack response simulation system based on SDN, comprising:
[0016] The network topology building module is used to create a network topology including hosts, switches, and controllers through Mininet scripts, and simulate actual network performance by setting topology type, bandwidth, and latency parameters;
[0017] Vulnerability identification module, which is used to configure vulnerability attributes including vulnerability number, hazard level, impact scope and repair suggestions for hosts in JSON format, and supports fast editing and batch allocation of vulnerabilities;
[0018] An attack simulation module, used to select an attack strategy based on the host vulnerability identification and execute a simulated attack, wherein the attack strategy includes an exploit attack and a denial of service attack;
[0019] The monitoring and response module is used to monitor network traffic and host status in real time through the SDN controller, identify abnormal behavior and trigger response mechanisms including traffic restriction, host isolation and data flow rerouting;
[0020] The repair and log module is used to automatically push repair suggestions and generate repair strategies after detecting host vulnerabilities, automatically configure and repair vulnerable hosts through network topology, and generate logs including vulnerability identification information, attack behavior records, and response measures details.
[0021] In a third aspect, the invention provides the following technical solution: a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned SDN-based large-scale host vulnerability identification and attack response simulation method when executing the computer program.
[0022] In a fourth aspect, the present invention provides the following technical solution: a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the above-mentioned SDN-based large-scale host vulnerability identification and attack response simulation method is implemented.
[0023] The present invention has the following beneficial effects:
[0024] 1. In the present invention, by configuring vulnerability attributes in JSON format (such as vulnerability number, hazard level, and impact range) for each host node and utilizing the centralized parsing capability of the SDN controller, attackers are supported to detect and locate target hosts based on specific vulnerability features. Compared with traditional static rules or simplified models, this method can accurately reproduce the exploitation process of complex vulnerabilities (such as the multidimensional characteristics described in CVE) and respond quickly through real-time monitoring and dynamic adjustment (such as traffic restriction and host isolation) when an attack occurs, thereby significantly improving the simulation capability of the network security simulation environment for real attack scenarios and solving the limitation that traditional methods are difficult to reflect vulnerability details.
[0025] 2. In the present invention, in large-scale networks (such as hundreds to thousands of host nodes), the method utilizes the centralized control characteristics of SDN, builds a flexible network topology through Mininet scripts, and supports batch allocation and rapid editing of vulnerability attributes; compared with traditional simulation methods that are limited by the processing capabilities of small and medium-sized networks, this method can maintain simulation efficiency and management accuracy when the number of nodes increases significantly through standardized vulnerability identification and dynamic resource scheduling (such as data flow rerouting), providing technical support for studying attack behaviors and defense strategies in complex networks.
[0026] 3. In the present invention, the network traffic and host status are monitored in real time through the SDN controller, and various response mechanisms (such as traffic filtering and adding firewall rules) are triggered after abnormal behavior is detected, thereby achieving a rapid response to attacks. Traditional methods mostly rely on fixed rules and are difficult to adapt to changing attack methods. However, this method can quickly mitigate the impact and restore network functions when an attack occurs by dynamically adjusting resource allocation strategies (such as bandwidth limitation or route switching), reflecting the ability to adapt to complex attack scenarios.
[0027] 4. In the present invention, after a host vulnerability is detected, the SDN controller automatically pushes repair suggestions and executes automated configuration (such as software updates or port closures), and generates detailed vulnerability and attack logs (including attack types, response measures, etc.); compared with traditional manual repairs or simulation methods that lack records, this function reduces the time cost of manual intervention, and provides a data basis for subsequent security analysis and policy optimization, improving the maintainability and traceability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 This is an implementation flow chart of a large-scale host vulnerability identification and attack response simulation method based on SDN proposed by the present invention;
[0029] Figure 2 A schematic diagram of host attribute description in a simulated DDoS attack scenario of a large-scale host vulnerability identification and attack response simulation method based on SDN proposed by the present invention;
[0030] Figure 3 This is a schematic diagram of the operation of extracting host bandwidth attribute items from a traffic monitoring script of a large-scale host vulnerability identification and attack response simulation method based on SDN proposed by the present invention;
[0031] Figure 4 A schematic diagram of abnormal behavior of a host downtime caused by a DDoS attack according to a large-scale host vulnerability identification and attack response simulation method based on SDN proposed by the present invention;
[0032] Figure 5 This is an implementation architecture diagram of an SDN architecture based on the present invention that uses JSON vulnerability attributes to complete attack response simulation. DETAILED DESCRIPTION
[0033] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0034] Embodiment 1
[0035] Reference Figure 1-Figure 5 In a first embodiment of the present invention, the present invention provides a large-scale host vulnerability identification and attack response simulation method based on SDN, comprising the following steps:
[0036] Step 1: Create a network topology using the Mininet script. The network topology includes hosts, switches, and controllers. The SDN controller is used to centrally manage traffic and node status in the network topology. The network performance in the actual scenario is simulated by setting the topology type, bandwidth, and delay parameters.
[0037] Step 2: In the SDN network environment, vulnerability attributes are configured for the host in JSON format. The vulnerability attributes include vulnerability number, hazard level, impact range, and repair suggestions. The host vulnerability attributes can be quickly edited and batch assigned through scripts to achieve automated vulnerability identification, so as to generate a topology node that identifies the vulnerability information.
[0038] Step 3: Based on the host vulnerability identification, select the corresponding attack strategy and execute the simulated attack. Monitor the network traffic and host status in real time through the SDN controller, identify abnormal behavior and trigger the response mechanism. The response mechanism includes traffic restriction, host isolation and data flow rerouting based on OpenFlow rules to simulate the defense mechanism in network attacks.
[0039] Specifically, in step 1, the Mininet script is written in Python language, and the network topology is defined by calling the Topo class in the Mininet library, for example, a tree topology (TreeTopo, depth 3, fan-out 10) with 100 host nodes is created, each host is assigned a unique IP address (such as 192.168.1.1 to 192.168.1.100), and the switch uses the OVSSwitch class to implement OpenFlow1.3 protocol support. The bandwidth parameter can be set to a range of 10Mbps to 1Gbps, and the delay parameter is configured to 1ms to 100ms through the tc command to simulate an enterprise network or data center environment. The SDN controller can be Ryu, ONOS or Floodlight. For example, when using the Ryu controller, the flow table rules are configured through the RESTAPI interface to achieve precise control of the traffic on each switch port. In the actual scenario simulation, background traffic can be introduced (such as using iperf to generate TCP / UDP data streams) to make the network load reach 50%-80% to be close to the real operating environment. In step 2, the vulnerability attributes in JSON format are generated through a script. For example, the vulnerability configuration of a host node is {"vuln_id":"CVE-2023-1234","severity":"High","impact":"Remote Code Execution","fix":"Upgrade to v2.1.3"}. When batch allocation is supported, the vulnerability data can be imported into 1000 host nodes through Python's json module. Vulnerability editing is implemented through a graphical interface, and users can enter manually. After editing, it is synchronized to the SDN controller database in real time. In step 3, the attack strategy is selected based on the vulnerability type. For example, the Metasploit framework is used to generate a payload for the exploit attack against CVE-2023-1234, and the attack frequency can be set to 10 times per second for 30 seconds. The SDN controller collects traffic data through the sFlow protocol with a sampling rate of 1 / 1000. When abnormal behavior (such as a sudden increase in traffic to 90% of the bandwidth) triggers an alarm, it automatically executes traffic restriction rules (limited to 20% of the original traffic). Host isolation is achieved by deleting the corresponding table entries in the switch flow table, and data flow rerouting is adjusted to the backup link by calculating the shortest path (such as the Dijkstra algorithm).
[0040] The network topology created in step 1 supports tree, mesh or ring topology types. The SDN controller communicates with the switch through the OpenFlow protocol to flexibly schedule and monitor network traffic in real time. The method is applied to large-scale network environments, supports simulation of hundreds to thousands of host nodes, and improves simulation efficiency and system scalability through centralized management.
[0041] Specifically, when the tree topology is implemented, the backbone switch is connected to 10 sub-switches, each sub-switch is connected to 10 hosts, a total of 100 nodes, and the topology depth is 2, which is suitable for simulating hierarchical networks; the mesh topology can be designed as a 5x5 matrix, with a total of 25 switches, each switch is connected to 4 hosts, a total of 100 nodes, suitable for distributed environments; the ring topology connects 10 switches in series, each switch is connected to 10 hosts, suitable for testing loop scenarios. In OpenFlow protocol communication, the controller sends 10 flow table rules to the switch per second. Each rule contains a matching field (such as source IP, destination port) and an action field (such as forwarding, discarding). The rules are stored in the switch's TCAM, and the capacity supports 100,000 rules. Flexible scheduling examples include raising the traffic priority from host A to host B to the highest (DSCP value is 46) to ensure that the delay is less than 5ms; real-time monitoring detects topology changes through the controller periodically sending LLDP messages (once every 5 seconds), and combines the SNMP protocol to collect switch port statistics (such as packet loss rate, bandwidth utilization). In terms of large-scale network support, the simulation environment can be expanded to 2,000 host nodes. The controller load is reduced through shard management (each 500 nodes is a group), and the simulation efficiency is improved by 30%. The system scalability is reflected in the support for dynamic addition of hosts (implemented through the CLI command net.addHost()). New nodes do not need to restart the network, which takes about 1 second.
[0042] The JSON format vulnerability attributes in step 2 also include vulnerability type, affected software version and attack conditions. The SDN controller parses the JSON vulnerability attributes of the host node through the vulnerability scanning module, extracts the vulnerability feature information, and formulates an attack plan based on the vulnerability feature information. The attack plan includes target host selection and attack method determination.
[0043] Specifically, in the JSON vulnerability attributes, the vulnerability types include buffer overflow, SQL injection, etc., such as {"type":"buffer overflow","affected_version":"Apache2.4.39","condition":"unverified input length"}. The data is stored in MongoDB, and the controller queries through RESTfulAPI. The size of each record is about 1KB. The vulnerability scanning module uses open source tools such as OpenVAS. The scanning cycle is set to 10 minutes. It takes about 2 hours to cover 1,000 hosts. After the scan results generate an XML report, the Python script parses the vulnerability features (such as the severity level is divided into four levels: low, medium, high, and emergency). In the formulation of the attack plan, the controller matches the Exploit-DB database according to the vulnerability number (such as CVE-2021-3456), selects the corresponding attack script (such as the buffer overflow attack implemented in Python), and the target host is locked by the IP address (such as 192.168.1.10). After the attack method is determined, the attack traffic (such as 1,000 malformed data packets) is generated, and the attack arrival rate is verified to be more than 95% through the switch port mirroring function. The parsing process supports multi-threaded processing, with each thread processing 50 host nodes, and the parsing time is shortened to less than 30 seconds.
[0044] The attack strategies in step 3 include one or more attacks targeting host vulnerabilities and denial of service attacks. Each attack type supports configuration of different attack strengths, frequencies, and durations. After identifying abnormal behavior, the SDN controller automatically adjusts network traffic according to preset defense strategies. Defense strategies include enabling traffic filtering, adding firewall rules, or activating intrusion detection and prevention systems to mitigate the impact of attacks and ensure network security.
[0045] Specifically, in the attack examples, the attack script injects 500 bytes of overlong data to trigger the target host service crash, with a success rate of 90% for the buffer overflow vulnerability; the denial of service attack uses the hping3 tool to send 100,000 SYN packets per second for 5 minutes, causing the target host bandwidth to occupy 100%; the cross-site scripting attack constructs malicious HTTP requests (such as <script>alert('XSS')< / script>) tests the Web service at a frequency of 50 times per second; the malware propagation simulates the WannaCry worm, which propagates through the SMB protocol vulnerability (CVE-2017-0144) and infects one host every 10 seconds. In the defense strategy, the traffic filtering rules are based on the matching of the five-tuple (source IP, destination IP, protocol, source port, destination port), and the bandwidth is restored to 80% of the normal level after discarding abnormal traffic; firewall rules are added through the controller API, such as ryu.ofproto.oxm_fields.match_ip_proto(6) to limit TCP traffic; the IDS / IPS system integrates Snort, and the detection rules cover 5,000 attack signatures, with a false alarm rate of less than 5%. After activation, it can block 90% of known attack traffic. The entire defense process is automated and the response time is less than 1 second.
[0046] It also includes real-time interaction with the host through the SDN controller. After detecting a host vulnerability, it automatically pushes vulnerability repair suggestions and generates repair strategies, repairs vulnerable hosts through automatic configuration of the network topology, and tracks the host status in real time during the repair process. At the same time, it generates detailed vulnerability and attack logs, which include vulnerability identification information, attack behavior records, and response measures details to support subsequent analysis and optimization.
[0047] Specifically, real-time interaction is achieved through the heartbeat mechanism between the controller and the host. A Ping request is sent every 5 seconds. If the host response delay exceeds 500ms, the vulnerability detection is triggered. The repair suggestion push adopts JSON format, such as {"vuln_id":"CVE-2022-5678","fix":"Install patch KB12345"}, and is distributed to the target host through the SSH protocol (batch processing of 100 hosts takes about 20 seconds). The automated repair strategy includes updating the software version and closing the vulnerable port (such as port 445). The repair process is executed by scripts with a success rate of 95%. Real-time tracking uses the top command to monitor the host CPU and memory usage, and record the status snapshot after abnormal recovery. The log generation module records data once a minute. The log file format is CSV, containing fields such as timestamp, host IP, vulnerability ID, attack type, response measures, and repair status. The size of a single attack log is about 500KB, which supports importing subsequent analysis tools (such as Wireshark). During optimization, the potential attack path can be predicted through machine learning models (such as random forests) with an accuracy of 85%.
[0048] It also supports external interface modules to connect to external vulnerability databases for automatic synchronization of vulnerability information, and dynamically configures host vulnerability properties and monitors simulation effects in real time through a graphical interface.
[0049] Specifically, the external interface module is developed based on the Flask framework, provides a RESTful API (such as / api / vuln_sync), connects to the CVE database (such as NVD), synchronizes vulnerability data every 24 hours, and synchronizes about 100,000 records at a time, which takes about 15 minutes. The network topology construction module is based on Mininet version 2.3.0. Through the Miniedit visual interface, it supports the rapid creation of a grid topology containing up to 500 hosts. Users can use Miniedit to intuitively design the network structure and flexibly configure the connections between hosts, switches, and controllers. The monitoring effect display includes a traffic curve chart (based on Pyplot drawing, refreshed once a second) and a host status heat map. Users can run the control script and view the response log. The interface supports multi-user concurrent access and supports up to 50 users operating at the same time.
[0050] The SDN controller monitors network traffic and attack characteristics in real time and dynamically adjusts the network's resource allocation strategy, including adjusting traffic routing and restricting resource access of affected hosts, to simulate the real attack response process and prevent the continued impact of the attack.
[0051] Specifically, real-time monitoring is achieved through the built-in traffic analysis module of the controller, which collects 1,000 data packets per second. The analysis indicators include bandwidth occupancy (in Mbps), packet loss rate (in %), and delay (in ms). If the bandwidth suddenly increases to more than 90%, it is determined to be an attack. In the resource allocation strategy adjustment, the traffic routing uses the OSPF protocol to calculate the new path. For example, the traffic is switched from link A (bandwidth is fully loaded) to link B (bandwidth occupancy is 30%), and the switching takes about 300ms; resource limitation sets the bandwidth upper limit through the tc command. After the limit, the target host traffic is reduced to 5Mbps to prevent downtime. Continuous impact prevention includes regular checks on the host survival status (through ARP requests, once every 10 seconds). If an abnormality is found (such as the host is offline), the service is automatically restarted. The entire process simulates the emergency response of a real enterprise network with a success rate of 98%.
[0052] Embodiment 2:
[0053] Reference Figure 1 In a second embodiment of the present invention, the present invention provides a large-scale host vulnerability identification and attack response simulation system based on SDN, including:
[0054] The network topology building module is used to create a network topology including hosts, switches, and controllers through Mininet scripts, and simulate actual network performance by setting topology type, bandwidth, and latency parameters;
[0055] Vulnerability identification module, which is used to configure vulnerability attributes including vulnerability number, hazard level, impact scope and repair suggestions for hosts in JSON format, and supports fast editing and batch allocation of vulnerabilities;
[0056] Attack simulation module, used to select attack strategies based on host vulnerability identification and execute simulated attacks. Attack strategies include exploitation attacks and denial of service attacks.
[0057] The monitoring and response module is used to monitor network traffic and host status in real time through the SDN controller, identify abnormal behavior and trigger response mechanisms including traffic restriction, host isolation and data flow rerouting;
[0058] The repair and log module is used to automatically push repair suggestions and generate repair strategies after detecting host vulnerabilities, automatically configure and repair vulnerable hosts through network topology, and generate logs including vulnerability identification information, attack behavior records, and response measures details.
[0059] Specifically, the network topology construction module is based on Mininet 2.3.0 version, supports the creation of a grid topology with 500 hosts, bandwidth parameters range from 1Mbps to 10Gbps, latency ranges from 0.1ms to 500ms, runs on Ubuntu 20.04 system, and occupies about 2GB of memory. The vulnerability identification module is developed using Python 3.8, JSON files are stored on the local disk (each host file is about 2KB), supports importing the NVD database format, and batch allocation is processed through multi-threading (50 hosts per thread), which takes about 10 seconds. The attack simulation module integrates Metasploit and hping3. Attack types include SYN flooding (100,000 packets per second) and SQL injection (100 requests per second). The CPU occupancy is about 30% during runtime. The monitoring and response module is based on the Ryu controller, with a flow monitoring frequency of 10 times per second. The response mechanism is issued through the OpenFlow1.3 flow table, such as deleting flow table items (flow_mod(del)) when isolating the host, and adding new table items (flow_mod(add)) when rerouting. The response delay is less than 100ms. The repair and log module executes repair commands in batches through SSH, and the logs are stored in the SQLite database. Each record contains timestamp, IP, and attack details. A single simulation generates a log of about 1MB, which can be exported to JSON format for external analysis.
[0060] Embodiment 3
[0061] The third embodiment of the present invention is based on the same inventive concept. The present invention proposes a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the steps of the SDN-based large-scale host vulnerability identification and attack response simulation method of the above embodiment.
[0062] Embodiment 4
[0063] The fourth embodiment of the present invention is based on the same inventive concept. The present invention proposes a computer device, and the terminal includes: a processor and a memory; the processor and the memory communicate with each other; the memory is used to store instructions; the processor is used to execute the instructions in the memory, and execute the SDN-based large-scale host vulnerability identification and attack response simulation method of the above embodiment.
[0064] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0065] Finally, it should be noted that the above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, it is still possible for those skilled in the art to modify the technical solutions described in the aforementioned embodiments or to make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A large-scale host vulnerability identification and attack response simulation method based on SDN, characterized in that: The following steps are involved: Step 1: Create a network topology using the Mininet script. The network topology includes hosts, switches, and controllers. The SDN controller is used to centrally manage traffic and node status in the network topology. The network performance in the actual scenario is simulated by setting the topology type, bandwidth, and delay parameters. Step 2: In the SDN network environment, vulnerability attributes are configured for the host in JSON format. The vulnerability attributes include vulnerability number, hazard level, impact range, and repair suggestions. The host vulnerability attributes can be quickly edited and batch assigned through scripts to achieve automated vulnerability identification, so as to generate a topology node that identifies the vulnerability information. Step 3: Based on the host vulnerability identification, select the corresponding attack strategy and execute the simulated attack. Monitor the network traffic and host status in real time through the SDN controller, identify abnormal behavior and trigger the response mechanism. The response mechanism includes traffic restriction, host isolation and data flow rerouting based on OpenFlow rules to simulate the defense mechanism in network attacks.
2. The SDN-based large-scale host vulnerability identification and attack response simulation method according to claim 1 is characterized in that: The network topology created in step 1 supports tree, grid or ring topology types. The SDN controller communicates with the switch through the OpenFlow protocol to flexibly schedule and monitor network traffic in real time. The method is applied to large-scale network environments, supports simulation of hundreds to thousands of host nodes, and improves simulation efficiency and system scalability through centralized management.
3. The SDN-based large-scale host vulnerability identification and attack response simulation method according to claim 1 is characterized in that: The JSON format vulnerability attributes in step 2 also include vulnerability types, affected software versions, and attack conditions. The SDN controller parses the JSON vulnerability attributes of the host node through a vulnerability scanning module, extracts vulnerability feature information, and formulates an attack plan based on the vulnerability feature information. The attack plan includes target host selection and attack method determination.
4. The SDN-based large-scale host vulnerability identification and attack response simulation method according to claim 1 is characterized in that: The attack strategy in step 3 includes one or more of an exploit attack against a host vulnerability and a denial of service attack, and each attack type supports configuration of different attack intensity, frequency, and duration; After identifying abnormal behavior, the SDN controller automatically adjusts network traffic according to a preset defense strategy, which includes enabling traffic filtering, adding firewall rules, or activating an intrusion detection and prevention system to mitigate the impact of attacks and ensure network security.
5. The SDN-based large-scale host vulnerability identification and attack response simulation method according to claim 1 is characterized in that: It also includes real-time interaction between the SDN controller and the host. After detecting a host vulnerability, the SDN controller pushes vulnerability repair suggestions to the affected host and generates a repair strategy in collaboration with the external vulnerability management system. Through traffic scheduling and policy adjustment, the load of the attacked host is reduced, and detailed vulnerability and attack logs are generated, including vulnerability identification information, attack behavior records, and response measures to support subsequent analysis and optimization.
6. The SDN-based large-scale host vulnerability identification and attack response simulation method according to claim 1 is characterized in that: It also supports the connection of external interface modules with external vulnerability databases to automatically synchronize vulnerability information, dynamically configure host vulnerability properties and monitor simulation effects in real time through a graphical interface.
7. The SDN-based large-scale host vulnerability identification and attack response simulation method according to claim 1 is characterized in that: The SDN controller dynamically adjusts the network's resource allocation strategy by monitoring network traffic and attack characteristics in real time, including adjusting traffic routing and restricting resource access of affected hosts, to simulate a real attack response process and prevent the continued impact of the attack.
8. A large-scale host vulnerability identification and attack response simulation system based on SDN, characterized in that: The SDN-based large-scale host vulnerability identification and attack response simulation method used in any one of claims 1 to 7 comprises: The network topology building module is used to create a network topology including hosts, switches, and controllers through Mininet scripts, and simulate actual network performance by setting topology type, bandwidth, and latency parameters; Vulnerability identification module, which is used to configure vulnerability attributes including vulnerability number, hazard level, impact scope and repair suggestions for hosts in JSON format, and supports fast editing and batch allocation of vulnerabilities; An attack simulation module, used to select an attack strategy based on the host vulnerability identification and execute a simulated attack, wherein the attack strategy includes an exploit attack and a denial of service attack; The monitoring and response module is used to monitor network traffic and host status in real time through the SDN controller, identify abnormal behavior and trigger response mechanisms including traffic restriction, host isolation and data flow rerouting; The repair and log module is used to automatically push repair suggestions and generate repair strategies after detecting host vulnerabilities, automatically configure and repair vulnerable hosts through network topology, and generate logs including vulnerability identification information, attack behavior records, and response measures details.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the SDN-based large-scale host vulnerability identification and attack response simulation method is implemented.
10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the SDN-based large-scale host vulnerability identification and attack response simulation method is implemented.
Citation Information
Patent Citations
SYN Flooding network attack scene reproduction method
CN114189354A
Virtualization security simulation method and system for complex network scene, processor and storage medium
CN118487842A
Systems and methods for detecting hidden vulnerabilities in enterprise networks
US20220046046A1
Cited By
Method and system for predicting life stage of vulnerability, storage medium and electronic equipment
CN121145219A