Network security exercise management system and method

By designing a network security exercise management system, using scene generation, real-time adjustment and data analysis modules to simulate and adjust network attack scenarios, the problems of more manual intervention, low execution efficiency and poor scalability in existing network security exercises are solved, and intelligent and efficient network security exercises are achieved.

CN120031685APending Publication Date: 2025-05-23WEBRAY TECH BEIJING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510028799.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Existing cybersecurity exercises have the problems of more manual intervention, low execution efficiency and poor scalability, and it is difficult to deal with complex security threats.

Method used

Design a network security exercise management system, through scene generation modules, real-time adjustment modules and data analysis modules, simulate real network attack scenarios based on network security threat information, participants' skill level and historical data, and adjust the scenarios and evaluation results in real time.

Benefits of technology

It has achieved intelligence and efficiency of network security exercises, reduced manual intervention, improved exercise efficiency and scalability, and better responded to complex security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120031685A_ABST
    Figure CN120031685A_ABST
Patent Text Reader

Abstract

The invention provides a network security exercise management system and method. The system comprises a scene generation module, a real-time adjustment module and a data analysis module, wherein the scene generation module is used for generating an initialized attack scene according to network security threat information, the skill level of a network security exercise participant and historical exercise data; the real-time adjustment module is used for adjusting the initialized attack scene according to the exercise performance of the network security exercise participant in the initialized attack scene; and the data analysis module is used for analyzing the data in the network security exercise process and generating an analysis result of the network security exercise. According to the embodiment of the invention, the intellectualization and high efficiency of the network security exercise are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network security exercise management system and method. Background Art

[0002] With the rapid development and popularization of Internet technology, cybersecurity threats have become more complex and diverse. Hacker attacks, malware, phishing and other security incidents have occurred frequently, causing huge losses and risks to individuals, enterprises and countries.

[0003] In the current cybersecurity environment, with the continuous evolution of attack methods, traditional cybersecurity exercises often have technical defects such as excessive manual intervention, low execution efficiency, and poor scalability, making it difficult to cope with increasingly complex security threats. Summary of the invention

[0004] The present invention provides a network security exercise management system and method, which simulates real network attack scenarios according to network security threat information, the skill levels of network security exercise participants and historical exercise data, and effectively solves the problems of frequent manual intervention, low execution efficiency, poor scalability, etc. in existing network security exercises through real-time adjustment of attack scenarios and evaluation of network security exercise results, thereby realizing the intelligence and efficiency of network security exercises.

[0005] The present invention provides a network security exercise management system, comprising: Scenario generation module, real-time adjustment module and data analysis module; among them, The scenario generation module is used to generate an initialized attack scenario based on network security threat information, the skill level of network security exercise participants and historical exercise data; The real-time adjustment module is used to adjust the initialized attack scenario according to the exercise performance of the network security exercise participants in the initialized attack scenario; The data analysis module is used to analyze the data during the network security exercise and generate analysis results of the network security exercise.

[0006] According to a network security exercise management system provided by the present invention, the scenario generation module includes: Threat intelligence collection unit, scenario building unit and scenario optimization unit; among them, The threat intelligence collection unit is used to collect network security threat information; The scenario construction unit is used to construct an initialized attack scenario according to the network security threat information and the skill level of the network security exercise participants; The scenario optimization unit is used to optimize and adjust the initialized attack scenario according to historical exercise data.

[0007] According to a network security exercise management system provided by the present invention, the real-time adjustment module includes: Monitoring unit, analysis unit and adjustment unit; wherein, The monitoring unit is used to monitor the exercise performance of the participants of the network security exercise in real time; The analysis unit is used to analyze the data monitored by the monitoring unit to obtain analysis results; The adjustment unit is used to adjust the attack scenario according to the analysis result.

[0008] According to a network security exercise management system provided by the present invention, the data analysis module includes: data collection unit, analysis and processing unit, and suggestion generation unit; The data collection unit is used to collect network security exercise data; The analysis processing unit is used to analyze the network security exercise data to obtain the analysis result of the network security exercise; The suggestion generating unit is used to generate improvement suggestions for the network security exercise according to the analysis result of the network security exercise.

[0009] According to a network security exercise management system provided by the present invention, the network security exercise management system further includes: Analysis and display module: The analysis and display module is used to visually display the analysis results of network security exercises.

[0010] A network security exercise management system provided by the present invention also includes: Gamification element module: The gamification element module is used to determine the points and rankings of cybersecurity exercise participants based on their exercise performance.

[0011] A network security exercise management system provided by the present invention also includes: Feedback loop module: The feedback loop module is used to feed back the scores and rankings of the network security exercise participants to the scenario generation module to adjust the attack scenario.

[0012] The present invention also provides a network security exercise management method, comprising: Generates an initial attack scenario based on cybersecurity threat information, the skill level of cybersecurity exercise participants, and historical exercise data; Adjusting the initialized attack scenario according to the exercise performance of the cybersecurity exercise participants in the initialized attack scenario; Analyze the data during the cybersecurity exercise and generate analysis results of the cybersecurity exercise.

[0013] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the network security exercise management method as described above when executing the program.

[0014] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the network security exercise management method as described above is implemented.

[0015] The present invention also provides a computer program product, including a computer program, which implements the network security exercise management method as described above when executed by a processor.

[0016] The network security exercise management system and method provided by the present invention simulates real network attack scenarios based on network security threat information, the skill levels of network security exercise participants and historical exercise data, and through real-time adjustment of attack scenarios and evaluation of network security exercise results, effectively solves the problems of frequent manual intervention, low execution efficiency, poor scalability, etc. in existing network security exercises, thereby realizing the intelligence and efficiency of network security exercises. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0018] Figure 1 This is one of the schematic diagrams of the network security exercise management system provided by the present invention.

[0019] Figure 2 This is the second schematic diagram of the network security exercise management system provided by the present invention.

[0020] Figure 3 This is the third schematic diagram of the network security exercise management system provided by the present invention.

[0021] Figure 4 This is one of the structural diagrams of the network security exercise management system provided by the present invention.

[0022] Figure 5 This is the second structural diagram of the network security exercise management system provided by the present invention.

[0023] Figure 6 This is the third structural diagram of the network security exercise management system provided by the present invention.

[0024] Figure 7 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0026] Combine the following Figure 1-Figure 7 The network security exercise management system and method of the present invention are described.

[0027] In order to facilitate a clearer understanding of the technical solutions of the embodiments of the present application, some technical contents related to the embodiments of the present application are first introduced.

[0028] With the rapid development of network technology, network security threats are becoming increasingly serious. Traditional network security training and exercise methods often lack practicality and pertinence, and it is difficult to effectively improve the network security protection capabilities of participants. Especially when facing large-scale enterprises or cross-regional network systems, traditional exercise methods cannot simulate complex attack scenarios in a timely manner, and it is difficult to efficiently evaluate the actual effectiveness of protection measures. In addition, the existing system lacks sufficient automation, resulting in a large risk of manual operation errors during the execution and monitoring of exercises. Therefore, it is necessary to develop an automated network security exercise management system to improve exercise efficiency, optimize resource allocation, and be able to perform vulnerability detection, attack simulation and protection evaluation in real time and dynamically in a changing security environment, further enhancing the security protection capabilities of enterprises.

[0029] Figure 1 is a schematic diagram of the network security exercise management system provided by the present invention, such as Figure 1 As shown, the system includes the following: Scenario generation module, real-time adjustment module and data analysis module; among them, The scenario generation module is used to generate an initial attack scenario based on cybersecurity threat information, the skill level of cybersecurity exercise participants, and historical exercise data; The real-time adjustment module is used to adjust the initialized attack scenario according to the exercise performance of the network security exercise participants in the initialized attack scenario; The data analysis module is used to analyze the data during the network security exercise and generate the analysis results of the network security exercise.

[0030] Specifically, the network security exercise management system in the embodiments of the present application includes a scenario generation module, a real-time adjustment module, and a data analysis module. Data transmission and interaction are carried out among the modules through an internal communication protocol. Among them, the scenario generation module is used to generate an initial attack scenario according to network security threat information, the skill levels of network security exercise participants, and historical exercise data. That is, in the process of generating the initial attack scenario, not only the current network security threats are considered, but also the skill levels of network security exercise participants and historical exercise data are fully considered. As a result, the finally generated initial attack scenario is more in line with the actual situation, and thus vulnerability detection, attack simulation, and protection evaluation can be carried out more accurately and comprehensively, effectively enhancing the enterprise's security protection ability. Optionally, the network security threat information can be the currently popular network vulnerabilities and network virus information collected, or the network vulnerabilities built in the network topology. The historical exercise data can be the results of offense-defense drills in the historical exercise process, such as whether various vulnerabilities are successfully defended. Optionally, the skill levels of network security exercise participants can also be determined based on historical exercise data. Optionally, the initial attack scenario includes the network topology, attack strategies, and attack methods, etc.

[0031] Optionally, the real-time adjustment module is used to adjust the initial attack scenario according to the exercise performance of network security exercise participants in the initial attack scenario. That is, in the embodiments of the present application, the difficulty and complexity of the attack can be dynamically adjusted according to the performance of the participants during the exercise, ensuring the continuity and effectiveness of the exercise, achieving the balance between offense and defense, and effectively improving the offense-defense skill levels of offense-defense exercisers. Optionally, if the attacker successfully conducts a vulnerability attack within the preset time, the defense method and defense strategy can be changed based on the defender's instructions to enhance the confrontation with the attacker; or the attack targets of the attacker can be increased, and the attack strategy and attack method of the attacker can be changed based on the attacker's instructions to improve the offense-defense skill levels of both offense and defense sides.

[0032] Optionally, the data analysis module is used to analyze the data during the network security exercise and generate the analysis results of the network security exercise. Optionally, during the network security exercise, the initial attack scenario can be adjusted according to the exercise performance of network security exercise participants in the initial attack scenario, and the exercise performance of the offense-defenders in the adjusted attack scenario can be statistically counted in real time to generate the analysis results of the network security exercise, such as the number of successful attacks, attack frequency, and attack difficulty of the attacker, etc., and the number of successful defenses and defense difficulty of the defender can also be statistically counted.

[0033] The network security exercise management system in the embodiment of the present application simulates real network attack scenarios based on network security threat information, the skill levels of network security exercise participants and historical exercise data, and through real-time adjustment of attack scenarios and evaluation of network security exercise results, effectively solves the problems of existing network security exercises such as excessive manual intervention, low execution efficiency, and poor scalability, thereby realizing the intelligence and efficiency of network security exercises.

[0034] In one embodiment, the scene generation module includes: Threat intelligence collection unit, scenario building unit and scenario optimization unit; among them, The threat intelligence collection unit is used to collect network security threat information; The scenario construction unit is used to construct an initialized attack scenario based on cybersecurity threat information and the skill level of cybersecurity exercise participants; The scenario optimization unit is used to optimize and adjust the initialized attack scenario based on historical exercise data.

[0035] Specifically, the scenario generation module in the embodiment of the present application includes: a threat intelligence collection unit, a scenario construction unit and a scenario optimization unit; wherein the threat intelligence collection unit is used to collect network security threat information. Optionally, the collected network security threat information can be currently popular network vulnerabilities and network virus information, or it can be a network vulnerability built into the network topology. The scenario construction unit is used to construct an initialized attack scenario according to the network security threat information and the skill level of the network security exercise participants, that is, to construct an initialized attack scenario according to the current network security threat information and the skill level of the network security exercise participants. Further, in order to make the constructed attack scenario both practical and challenging, the initialized attack scenario is further optimized and adjusted according to the historical exercise data in the embodiment of the present application, such as deleting the vulnerabilities with a large number of successful defenses in the historical exercises from the initialized attack scenario, and adding dangerous vulnerabilities with a small number of successful defenses. That is, in the generation process of the attack scenario, not only the current network security threats are considered, but also the skill level and historical exercise data of the network security exercise participants are fully considered, so that the final generated attack scenario is more in line with reality, and then it is also possible to more accurately and comprehensively perform vulnerability detection, attack simulation and protection evaluation, effectively enhancing the security protection capabilities of the enterprise.

[0036] In the network security exercise management system of the above-mentioned embodiment, the threat intelligence collection unit is used to collect network security threat information, the scenario construction unit is used to construct an initialized attack scenario based on the network security threat information and the skill level of the network security exercise participants, and the scenario optimization unit is used to optimize and adjust the initialized attack scenario based on historical exercise data, so that the final generated attack scenario is both realistic and challenging, and vulnerability detection, attack simulation and protection assessment can be performed more accurately and comprehensively, effectively enhancing the enterprise's security protection capabilities.

[0037] In one embodiment, the real-time adjustment module includes: Monitoring unit, analysis unit and adjustment unit; wherein, The monitoring unit is used to monitor the performance of cybersecurity exercise participants in real time; The analysis unit is used to analyze the data monitored by the monitoring unit to obtain analysis results; The adjustment unit is used to adjust the attack scenario according to the analysis result.

[0038] Specifically, the real-time adjustment module in the embodiment of the present application includes a monitoring unit, an analysis unit and an adjustment unit; wherein the monitoring unit is used to monitor the exercise performance of the participants of the network security exercise in real time, such as monitoring the participants' attack and defense strategies, attack and defense methods, and attack and defense reaction speeds in real time. The analysis unit is used to analyze the data monitored by the monitoring unit to determine whether the participants' attack and defense strategies and attack and defense methods are reasonable and whether the attack and defense measures are timely and fast. Optionally, the analysis unit can be trained based on the attack and defense strategies of existing vulnerabilities, so that the trained analysis unit can accurately determine whether the participants' attack and defense strategies, attack and defense methods are reasonable and whether the attack and defense measures are timely and fast. The adjustment unit dynamically adjusts the difficulty and complexity of the attack scenario according to the analysis results and the instructions of the participants, realizing the high intelligence and efficiency of the network security exercise management system, which can significantly improve the network security protection capabilities of the participants.

[0039] In the network security exercise management system of the above-mentioned embodiment, the monitoring unit monitors the exercise performance of the network security exercise participants in real time; the analysis unit analyzes the data monitored by the monitoring unit to obtain analysis results; the adjustment unit adjusts the attack scenario according to the analysis results, thereby realizing the high intelligence and efficiency of the network security exercise management system, which can significantly enhance the network security protection capabilities of the participants.

[0040] In one embodiment, the data analysis module includes: data collection unit, analysis and processing unit, and suggestion generation unit; The data collection unit is used to collect cybersecurity exercise data; The analysis and processing unit is used to analyze the network security exercise data to obtain the analysis results of the network security exercise; The suggestion generating unit is used to generate improvement suggestions for the network security exercise according to the analysis results of the network security exercise.

[0041] Specifically, the data analysis module in the embodiment of the present application includes a data collection unit, an analysis processing unit and a suggestion generation unit; wherein the data collection unit is used to collect network security exercise data, such as personnel data of attack and defense exercises, network topology data, network equipment log data, etc., that is, to collect data resources from various security devices and systems, and provide solid data support for network security exercises. The analysis processing unit is used to analyze the network security exercise data to obtain the analysis results of the network security exercise; such as by analyzing the network security exercise data, the evaluation results of the participants' attack and defense exercise performance and the identification results of security vulnerabilities and weak links are obtained, so that network management personnel can have a more comprehensive understanding of the security status of the system. The suggestion generation unit is used to generate improvement suggestions for network security exercises based on the analysis results of network security exercises, such as, based on the analysis results of network security exercises, proposing specific improvement suggestions for attack and defense strategies and directions for further learning and strengthening of attack and defense skills to attack and defense exercise personnel, effectively improving the skills of attack and defense exercise personnel.

[0042] In the network security exercise management system of the above-mentioned embodiment, the data collection unit is used to collect network security exercise data; the analysis and processing unit is used to analyze the network security exercise data to obtain the analysis results of the network security exercise; the suggestion generation unit is used to generate improvement suggestions for the network security exercise based on the analysis results of the network security exercise, and to provide the attack and defense exercise personnel with directions for further learning and strengthening of attack and defense skills, thereby improving the skills and network security protection capabilities of the attack and defense exercise personnel, so that network management personnel can have a more comprehensive understanding of the security status of the system and effectively enhance the security protection capabilities of the enterprise.

[0043] In one embodiment, the network security exercise management system further includes: Analysis and display module: The analysis and display module is used to visualize the analysis results of network security exercises.

[0044] Specifically, the analysis and display module in the embodiment of the present application is used to visualize the analysis results of the network security exercise, and present the complex security information in the form of intuitive charts. Optionally, the analysis and display module in the embodiment of the present application includes an image design unit, an interactive exploration unit, and an achievement display unit. Among them, the image design unit is used to convert complex security data and the analysis results of network security exercises into easy-to-understand charts and images; the interactive exploration unit allows participants to dig deep into the details and trends in the charts through operations; the achievement display unit gives feedback based on the depth and accuracy of the image analysis to the participants, and displays their exploration results in an intuitive way.

[0045] In the network security exercise management system of the above embodiment, the analysis and display module visualizes the analysis results of the network security exercise and presents complex security information in the form of intuitive charts, thereby realizing the intelligence, efficiency and visualization of the network security exercise.

[0046] In one embodiment, the network security exercise management system further includes: Gamification element module: The gamification element module is used to determine the points and rankings of cybersecurity exercise participants based on their exercise performance.

[0047] Specifically, the network security exercise management system in the embodiment of the present application also includes a gamification element module. Among them, the gamification element module is used to determine the points and rankings of network security exercise participants according to the exercise performance of network security exercise participants, that is, to design network security exercises into challenging and interesting games, stimulate the interest and motivation of participants, and improve the participation and effect of exercises. Optionally, the gamification element module in the embodiment of the present application includes a game design unit, a points management unit, and a ranking management unit. Among them, the game design unit is responsible for designing game rules and scenarios; the points management unit gives corresponding points rewards according to the performance of participants; and the ranking management unit ranks and displays participants according to the points. It should be noted that the network security exercise management system in the embodiment of the present application can simulate real network attack scenarios, evaluate and adjust the performance of participants in real time, provide data analysis and improvement suggestions, and integrate gamification elements to improve the participation and motivation of participants, realize the full process automation from scenario generation to data analysis, and dynamically adjust the difficulty. Compared with the manual setting of traditional exercises, its efficiency and accuracy are significantly improved, achieving the innovative purpose of automation.

[0048] In the network security exercise management system of the above embodiment, the network security exercise is designed into a challenging and interesting game through the gamification element module, which stimulates the interest and motivation of the participants and improves the participation and effect of the exercise.

[0049] In one embodiment, the network security exercise management system further includes: Feedback loop module: The feedback loop module is used to feed back the scores and rankings of the cybersecurity exercise participants to the scenario generation module to adjust the attack scenario.

[0050] Specifically, Figure 2 and Figure 3 As shown, the feedback loop module in the embodiment of the present application continuously learns and summarizes past exercise experience, and feeds back the points and rankings of the network security exercise participants to the scenario generation module. Then, the scenario generation module can effectively optimize and adjust the attack scenario according to the points and rankings of the network security exercise participants, thereby realizing the iteration of the attack scenario, and thus improving the quality and effect of future exercises, and realizing the intelligence and efficiency of network security exercises. Optionally, the feedback loop module in the embodiment of the present application includes a learning unit, an optimization unit, and a feedback unit; wherein the learning unit is responsible for learning past exercise experience and data; the optimization unit optimizes the system's scenario generation and evaluation mechanism according to the learning results; and the feedback unit feeds back the optimization results to other modules for further adjustment and improvement. It should be noted that the network security exercise management system in the embodiment of the present application realizes iterative optimization of the attack scenario design. This closed-loop feedback system not only improves the adaptability of the system, but also makes up for the limitations of single evaluation in traditional exercises through continuous improvement, forming the ability of continuous evolution. Exemplarily, the structure of the network security exercise management system in the embodiment of the present application is as follows Figure 4 , Figure 5 and Figure 6 shown.

[0051] In the network security exercise management system of the above-mentioned embodiment, the feedback loop module feeds back the points and rankings of the network security exercise participants to the scenario generation module, and then the scenario generation module can effectively optimize and adjust the attack scenarios according to the points and rankings of the network security exercise participants, thereby realizing the iteration of the attack scenarios, and thus improving the quality and effect of future exercises, thereby realizing the intelligence and efficiency of network security exercises.

[0052] Exemplarily, an embodiment of the present application further provides a network security exercise management method, including: Generates an initial attack scenario based on cybersecurity threat information, the skill level of cybersecurity exercise participants, and historical exercise data; Adjust the initial attack scenario based on the performance of the cybersecurity exercise participants in the initial attack scenario; Analyze the data during the cybersecurity exercise and generate analysis results of the cybersecurity exercise.

[0053] Specifically, the embodiment of the present application first generates an initialized attack scenario based on network security threat information, the skill level of network security exercise participants and historical exercise data. That is, in the generation process of the initialized attack scenario, not only the current network security threat is considered, but also the skill level and historical exercise data of the network security exercise participants are fully considered, so that the initialized attack scenario finally generated is more in line with reality, and vulnerability detection, attack simulation and protection evaluation can be performed more accurately and comprehensively, effectively enhancing the security protection capabilities of the enterprise. Optionally, the network security threat information can be the currently popular network vulnerabilities and network virus information collected, or it can be the network vulnerabilities built into the network topology. The historical exercise data can be the results of the attack and defense drills in the historical exercise process, such as whether each vulnerability is successfully defended. Optionally, the skill level of the network security exercise participants can also be determined based on historical exercise data. Optionally, the initialized attack scenario includes the topology of the network, the attack strategy and the attack method, etc.

[0054] Further, the initialized attack scenario can be adjusted according to the exercise performance of the participants in the network security exercise in the initialized attack scenario. That is, in the embodiment of the present application, the difficulty and complexity of the attack can be dynamically adjusted according to the performance of the participants in the exercise process, to ensure the continuity and effectiveness of the exercise, to achieve a balance between offense and defense, and to effectively improve the offensive and defensive skills of the participants in the exercise. Optionally, if the attacker successfully attacks the vulnerability within a preset time, the defense method and defense strategy can be changed based on the defender's instructions to enhance the confrontation with the attacker; or the attacker's attack target can be increased based on the attacker's instructions, and the attacker's attack strategy and attack method can be changed to improve the offensive and defensive skills of both the attacker and the defender.

[0055] Optionally, in the embodiment of the present application, the analysis results of the network security exercise are generated by analyzing the data during the network security exercise. Optionally, during the network security exercise, the initial attack scenario can be adjusted according to the exercise performance of the network security exercise participants in the initial attack scenario, and the exercise performance of the attacker and defender in the adjusted attack scenario can be counted in real time to generate the analysis results of the network security exercise, such as the number of successful attacks, attack frequency and attack difficulty of the attacker, etc., and the number of successful defenses and defense difficulty of the defender can also be counted.

[0056] The method of the embodiment of the present application simulates real network attack scenarios based on network security threat information, the skill levels of network security exercise participants and historical exercise data, and through real-time adjustment of attack scenarios and evaluation of network security exercise results, effectively solves the problems of existing network security exercises such as excessive manual intervention, low execution efficiency, and poor scalability, thereby realizing the intelligence and efficiency of network security exercises.

[0057] Figure 7 The figure illustrates a schematic diagram of the physical structure of an electronic device, which may include: a processor 7710, a communications interface 720, a memory 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 complete communication with each other through the communication bus 740. The processor 710 can call the logical instructions in the memory 730 to execute the network security exercise management method, which includes: generating an initialized attack scenario according to network security threat information, the skill levels of network security exercise participants, and historical exercise data; adjusting the initialized attack scenario according to the exercise performance of network security exercise participants in the initialized attack scenario; analyzing the data during the network security exercise process to generate an analysis result of the network security exercise.

[0058] In addition, when the logical instructions in the above-mentioned memory 730 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0059] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the network security exercise management method provided by the above-mentioned various methods, which includes: generating an initialized attack scenario according to network security threat information, the skill levels of network security exercise participants, and historical exercise data; adjusting the initialized attack scenario according to the exercise performance of network security exercise participants in the initialized attack scenario; analyzing the data during the network security exercise process to generate an analysis result of the network security exercise.

[0060] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the network security exercise management method provided by the above-mentioned methods, the method comprising: generating an initialized attack scenario based on network security threat information, the skill level of network security exercise participants and historical exercise data; adjusting the initialized attack scenario based on the exercise performance of the network security exercise participants in the initialized attack scenario; and analyzing the data during the network security exercise to generate analysis results of the network security exercise.

[0061] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0062] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0063] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A network security exercise management system, characterized in that: include: Scenario generation module, real-time adjustment module and data analysis module; among them, The scenario generation module is used to generate an initialized attack scenario based on network security threat information, the skill level of network security exercise participants and historical exercise data; The real-time adjustment module is used to adjust the initialized attack scenario according to the exercise performance of the network security exercise participants in the initialized attack scenario; The data analysis module is used to analyze the data during the network security exercise and generate analysis results of the network security exercise.

2. The network security exercise management system according to claim 1, characterized in that: The scene generation module comprises: Threat intelligence collection unit, scenario building unit and scenario optimization unit; among them, The threat intelligence collection unit is used to collect network security threat information; The scenario construction unit is used to construct an initialized attack scenario according to the network security threat information and the skill level of the network security exercise participants; The scenario optimization unit is used to optimize and adjust the initialized attack scenario according to historical exercise data.

3. The network security exercise management system according to claim 1, characterized in that: The real-time adjustment module comprises: Monitoring unit, analysis unit and adjustment unit; wherein, The monitoring unit is used to monitor the exercise performance of the participants of the network security exercise in real time; The analysis unit is used to analyze the data monitored by the monitoring unit to obtain analysis results; The adjustment unit is used to adjust the attack scenario according to the analysis result.

4. The network security exercise management system according to claim 1, characterized in that: The data analysis module includes: data collection unit, analysis and processing unit, and suggestion generation unit; The data collection unit is used to collect network security exercise data; The analysis processing unit is used to analyze the network security exercise data to obtain the analysis result of the network security exercise; The suggestion generating unit is used to generate improvement suggestions for the network security exercise according to the analysis result of the network security exercise.

5. The network security exercise management system according to any one of claims 1 to 4, characterized in that: The network security exercise management system further includes: Analysis and display module: The analysis and display module is used to visually display the analysis results of network security exercises.

6. The network security exercise management system according to any one of claims 1 to 4, characterized in that: The network security exercise management system further includes: Gamification element module: The gamification element module is used to determine the points and rankings of cybersecurity exercise participants based on their exercise performance.

7. The network security exercise management system according to any one of claims 1 to 4, characterized in that: The network security exercise management system further includes: Feedback loop module: The feedback loop module is used to feed back the scores and rankings of the network security exercise participants to the scenario generation module to adjust the attack scenario.

8. A network security exercise management method, characterized in that: include: Generates an initial attack scenario based on cybersecurity threat information, the skill level of cybersecurity exercise participants, and historical exercise data; Adjusting the initialized attack scenario according to the exercise performance of the cybersecurity exercise participants in the initialized attack scenario; Analyze the data during the cybersecurity exercise and generate analysis results of the cybersecurity exercise.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the network security exercise management method as claimed in claim 8 is implemented.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the network security exercise management method as claimed in claim 8 is implemented.