Method and device for constructing network target range of multi-layer network structure

By using Docker container technology to build a multi-layer network structure in the network shooting range, the problems of slow dispatch speed, high resource occupation and difficult adaptation in the existing technology are solved, and the effects of reducing costs, improving resource utilization and convenient deployment are achieved, providing an efficient network security training platform.

CN120034356APending Publication Date: 2025-05-23INTEGRITY TECH GRP INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510035200.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing kvm range system has slow issuance speed, high resource utilization, and difficult to adapt to privatize deployment. Moreover, the container range is mainly single-node scenarios, and the actual simulation environment is poor.

Method used

Docker container technology is used to build a network shooting range with multi-layer network structure, generate multi-layer architectures for internal networks, service networks and external networks, produce their own Docker image files, configure network services and routing, deploy containers and container instances, and develop network shooting range management systems and user interfaces.

Benefits of technology

It significantly reduces the cost of hardware procurement, maintenance and energy consumption, improves resource utilization and deployment convenience, can quickly respond to changes in training needs, adapt to diversified teaching and scientific research needs, and provide an efficient and practical training platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034356A_ABST
    Figure CN120034356A_ABST
Patent Text Reader

Abstract

The invention discloses a method for constructing a network target range of a multi-layer network structure. The method can construct a new network target range of the multi-layer network structure. By means of the Docker container technology, dependence on physical equipment and a traditional virtual machine is greatly reduced, and the hardware purchase cost, the maintenance cost and the energy consumption cost of target range construction are remarkably reduced. It can be understood that docker containerization is adopted, the starting speed is high, and the resource utilization rate is high; the docker containerization is adopted, so that the adaptation is simple, and the support of private deployment is relatively high; the networking function between the containers is achieved, and simulation of complex real scenes is supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network target range technology, and in particular to a method and device for constructing a network target range with a multi-layer network structure. Background Art

[0002] In today's digital age, the rapid development of network technology has made network security increasingly important. Enterprises, government agencies and various organizations are facing increasingly complex network threats, so the practical ability training of professional network security personnel has become the key. Traditional network security training ranges mainly rely on physical equipment or virtual machine technology. However, physical equipment construction of the range requires the purchase of a large number of expensive hardware equipment, which not only has high initial investment costs, but also complex maintenance in the later stage, and the cost of equipment replacement is also high. Although virtual machine technology has alleviated the hardware cost problem to a certain extent, it still has many shortcomings.

[0003] For example, the resource allocation of virtual machines is relatively fixed and difficult to flexibly adjust according to actual needs, resulting in low resource utilization. At the same time, its delivery speed is slow, and when multiple scenarios need to be quickly deployed for training, it often cannot meet the timeliness requirements. In addition, some traditional virtualization technologies, such as the private deployment and adaptation of the KVM range system, are difficult to adapt, which limits its application in specific security demand scenarios.

[0004] It is understandable that the prior art has the following problems:

[0005] 1. The existing KVM target range system uses KVM virtualization, which has a slow delivery speed and high resource usage. 2. The existing KVM target range is difficult to adapt to the private deployment of the information innovation. 3. The existing container target range is mostly single-node scenarios, which simulates the actual environment poorly. Summary of the invention

[0006] The present application provides a method and device for constructing a network range with a multi-layer network structure, so as to achieve the goal of greatly reducing the dependence on physical devices and traditional virtual machines with the help of Docker container technology, and significantly reducing the hardware procurement cost, maintenance cost and energy consumption cost of range construction.

[0007] In a first aspect, the present application provides a method for constructing a network target range with a multi-layer network structure, the method comprising:

[0008] Generate a multi-layer network structure target range architecture with an internal network, a service network and an external network; wherein the internal network, the service network and the external network in the multi-layer network structure target range architecture are all Docker networks; the internal network, the service network and the external network are respectively used to connect different networks;

[0009] Creating respective Docker image files for the internal network, the service network, and the external network; wherein the Docker image file corresponding to each network includes a preset type vulnerability environment corresponding to the network, and services and applications for simulating preset vulnerabilities;

[0010] Configure network services for the internal network, the service network and the external network respectively, and set up inter-network routing to simulate a real network environment; wherein the network service includes multiple network segments;

[0011] For the internal network, the service network and the external network, respectively configure corresponding containers and container instances, and connect the containers to the networks corresponding thereto; wherein the container instances corresponding to the networks are stored in the containers corresponding to the networks;

[0012] Develop a network range management system with the ability to control containers for starting, stopping, monitoring, and logging;

[0013] A user interface is configured to obtain a network target range with a multi-layer network structure; wherein the user interface is used for the user to select different vulnerability scenarios through the user interface and conduct actual combat exercises through the network target range.

[0014] In a second aspect, the present application provides a device for constructing a network range with a multi-layer network structure, the device comprising:

[0015] The first unit is used to generate a multi-layer network structure target range architecture having an internal network, a service network and an external network; wherein the internal network, the service network and the external network in the multi-layer network structure target range architecture are all Docker networks; the internal network, the service network and the external network are respectively used to connect different networks;

[0016] The second unit is used to prepare Docker image files corresponding to the internal network, the service network and the external network respectively; wherein the Docker image file corresponding to each network includes a preset type vulnerability environment corresponding to the network, and a service and application program for simulating the preset vulnerability;

[0017] The third unit is used to configure network services for the internal network, the service network and the external network respectively, and set inter-network routing to simulate a real network environment; wherein the network service includes multiple network segments;

[0018] A fourth unit is used to configure corresponding containers and container instances for the internal network, the service network, and the external network, respectively, and connect the containers to the networks corresponding thereto; wherein the container instances corresponding to the networks are stored in the containers corresponding to the networks;

[0019] Unit 5 is used to develop a network range management system with the ability to control containers for starting, stopping, monitoring, and logging;

[0020] The sixth unit is used to configure a user interface to obtain a network target range of a target multi-layer network structure; wherein the user interface is used for a user to select different vulnerability scenarios through the user interface and conduct actual combat exercises through the network target range.

[0021] In a third aspect, the present application provides a readable medium comprising execution instructions. When a processor of an electronic device executes the execution instructions, the electronic device executes any method described in the first aspect.

[0022] In a fourth aspect, the present application provides an electronic device, comprising a processor and a memory storing execution instructions, wherein when the processor executes the execution instructions stored in the memory, the processor executes any method described in the first aspect.

[0023] It can be seen from the above technical scheme that the present application provides a method for constructing a network range with a multi-layer network structure, and the method can construct a new network range with a multi-layer network structure; the present application greatly reduces the dependence on physical equipment and traditional virtual machines with the help of Docker container technology, and significantly reduces the hardware procurement cost, maintenance cost and energy consumption cost of range construction. In terms of deployment convenience, the containerized deployment method makes the range construction and maintenance process highly simplified, can quickly respond to changes in training needs, and greatly shortens the time cycle from planning to actual use. From the perspective of resource utilization, the application of container technology improves the flexibility and utilization of resource allocation, and can dynamically adjust resource allocation according to different training scenarios, avoiding idleness and waste of resources. In terms of flexibility, the present application can quickly adjust the network structure and container configuration of the range according to the actual training goals and network security research directions, and adapt to the diverse teaching and scientific research needs. In addition, its scalability is also very prominent, it is easy to add new vulnerability environments and attack scenarios (i.e., container instances), it is convenient to update training content in a timely manner, keep up with the development trend of network security technology, and provide network security personnel with an efficient, practical and forward-looking training platform, which has effectively promoted the cultivation and improvement of network security practical capabilities. That is, the Docker containerization is used in this application, which has fast startup speed and high resource utilization; the Docker containerization is simple to adapt to the trusted computing environment and has high support for private deployment; the inter-container networking function is realized, and complex real-life scenario simulation is supported.

[0024] The further effects of the above-mentioned non-conventional preferred manner will be described below in conjunction with specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the embodiments of the present application or the existing technical solutions, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0026] Figure 1 A schematic diagram of a process for constructing a network target range with a multi-layer network structure provided in this application;

[0027] Figure 2 A schematic diagram of the structure of a device for constructing a network target range with a multi-layer network structure provided by the present application;

[0028] Figure 3 A schematic diagram of the structure of an electronic device provided in this application. DETAILED DESCRIPTION

[0029] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0030] Various non-limiting implementations of the present application are described in detail below in conjunction with the accompanying drawings.

[0031] See also Figure 1 , shows a method for constructing a network target range of a multi-layer network structure in an embodiment of the present application. In this embodiment, the method may include the following steps:

[0032] S101: Generate a multi-layer network structure target range architecture with an internal network, a service network and an external network.

[0033] Among them, the internal network, the service network and the external network in the multi-layer network structure range architecture are all Docker networks. In other words, configure the Docker network: create three Docker networks, namely the internal network (used by the database), the service network (used by the Web application) and the external network (used by the firewall).

[0034] The internal network, the service network and the external network are used to connect to different networks respectively. The internal network is used to connect to a network for accessing an internal database of an operating system; the service network is used to connect to a network for accessing business services; and the external network is used to connect to a network for connecting to external devices.

[0035] This application first designs a multi-layer network structure of the target range architecture, including internal network, service network and external network, and each network level uses an independent Docker network isolation. First, design a docker container target range, which contains three layers of network, internal network, service network and external network. Students break into the target machine through the external network, and then use the target machine to have three-layer network access capabilities to attack machines in other areas.

[0036] S102: Creating corresponding Docker image files for the internal network, the service network, and the external network respectively.

[0037] Among them, the Docker image file corresponding to each network includes the preset type vulnerability environment corresponding to the network, and the services and applications used to simulate the preset vulnerabilities. Specifically, the Docker image file corresponding to the internal network includes the preset type vulnerability environment corresponding to the internal network, the vulnerabilities of the operating system corresponding to the internal network, and the vulnerabilities of the basic middleware; the Docker image file corresponding to the service network includes the preset type vulnerability environment corresponding to the service network and the vulnerabilities of the business services; the Docker image file corresponding to the external network includes the preset type vulnerability environment corresponding to the external network and the access entry.

[0038] In this embodiment, the specific method of making the Docker image files corresponding to the internal network, the service network and the external network respectively can be introduced as follows. According to the network security requirements corresponding to the internal network, the service network and the external network respectively, the Docker image files corresponding to the internal network, the service network and the external network respectively are generated according to various security vulnerabilities and simulated attack scenarios corresponding to the network security requirements corresponding to the internal network, the service network and the external network respectively.

[0039] It is understandable that for different network levels, Docker images containing various vulnerability environments can be created, and each image contains services and applications that simulate specific vulnerabilities. Docker images are the target machine images in the target range, but they are lightweight target machines. The image form of kvm in the existing technology starts slowly and has large image resources. The internal network corresponds to the vulnerabilities of the operating system and the vulnerabilities of the basic middleware (database, apache, nginx); the external network is equivalent to the access entrance; the service network refers to the vulnerabilities of business services (such as web). Creating a Docker image means: creating Docker images for web applications, databases, and firewalls respectively, and each image contains necessary services and vulnerabilities.

[0040] S103: configuring network services for the internal network, the service network and the external network respectively, and setting inter-network routing to simulate a real network environment.

[0041] Each network service includes multiple network segments. Specifically, based on the network security isolation principle, multiple network segments can be configured for the internal network, the service network and the external network, and the network segments corresponding to the internal network, the service network and the external network are all different.

[0042] It is understandable that network configuration is performed for the internal network, the service network, and the external network. Specifically, the Docker network needs to be configured, an independent network segment is allocated for each network level, and inter-network routing is set to simulate a real network environment. It should be noted that a container is equivalent to a host and can simulate a company's intranet environment, such as a database host, a personal host, and a web server host, each in a different network segment.

[0043] S104: For the internal network, the service network, and the external network, respectively configure corresponding containers and container instances, and connect the containers to the corresponding networks.

[0044] The container instance corresponding to the network is stored in the container corresponding to the network.

[0045] In this embodiment, containers can be deployed for the internal network, the service network, and the external network. Specifically, container instances can be deployed according to the range architecture design, and the containers can be connected to the corresponding network layers. Container refers to the abbreviation of an operating environment, and container resources refer to specific corresponding resources; when creating, the range determines which host to start based on the id and name of the image. Container instances are stored in containers, and container instances can be understood as cases that require simulated range attacks.

[0046] In this embodiment, service configuration can be performed for the internal network, the service network, and the external network. Network services, including Web servers, database servers, etc., are configured in the container to simulate a real service environment. It should be emphasized that network services can be understood as routing and switches. There is a network service in a range environment, and there can be multiple network segments in the network service. Each container resource is bound to multiple network cards to achieve intercommunication between containers in different network segments to simulate a real intranet environment.

[0047] In this embodiment, containers can be deployed: start the Web application container and connect to the service network, start the database container and connect to the internal network, start the firewall container and connect to the external network. Services can also be configured: configure Web services in the Web application container, configure database services in the database container, and configure firewall rules in the firewall container.

[0048] S105: Develop a network range management system with the ability to control containers to start, stop, monitor, and log.

[0049] In this embodiment, the monitoring function of the network range management system is specifically used to monitor the resource usage and operation status of the containers corresponding to the internal network, the service network and the external network; the logging function of the network range management system is specifically used to record the log records corresponding to the internal network, the service network and the external network, wherein the log records include records of user operations and key events during system operation.

[0050] It is understandable that a range management system is developed to implement functions such as starting, stopping, monitoring and logging of containers. Range management. A range management system with a web interface is developed to allow administrators to monitor container status and record user operation logs.

[0051] S106: Configure the user interface to obtain a network target range with a multi-layer network structure.

[0052] The user interface is used for the user to select different vulnerability scenarios through the user interface and conduct actual combat exercises through the network range. The actual combat exercises include: penetration testing, vulnerability exploitation and defense strategy verification.

[0053] In this embodiment, the user interface is further used to provide an interactive interface, in which different vulnerability scenarios are displayed to facilitate the user to select a vulnerability scenario.

[0054] Accordingly, the method further comprises:

[0055] In response to a vulnerability scenario selected by a user through the user interface, corresponding container configurations are deployed for containers of the internal network, the service network, and the external network respectively according to the vulnerability scenario selected by the user.

[0056] It should be noted that the user interface is provided to allow users to select different vulnerability scenarios and automatically deploy the corresponding container configuration. Among them, the container configuration is the configuration flag, which is the corresponding answer; the answer value successfully obtained after the service is attacked. This is used to determine the student's score in competitions or training services. The container configuration can be understood as an attack scenario, and a set of container range scenarios is issued.

[0057] For actual combat exercises, users can conduct actual combat exercises through the shooting range, including penetration testing, vulnerability exploitation, defense strategy verification, etc.

[0058] User operation: The user selects the attack scenario through the Web interface, the system automatically deploys the corresponding container configuration, and the user performs penetration testing. Penetration testing can be understood as returning an accessible target machine IP after sending the container target scenario, and the user performs penetration and attack and defense operations on this target machine IP.

[0059] It should be noted that the container range is an environment used to simulate real attack scenarios, mainly for security professionals to conduct experiments, learning and drills. It is usually used in the field of network security to help security personnel improve their practical skills by simulating various vulnerabilities and attack methods. The container range can quickly and automatically use Docker virtualization technology to build vulnerable cloud native target environments from simple to complex, and realize the automated construction of cloud native multi-level vulnerable scenarios.

[0060] In summary, the solution to be protected by this application is that the container range provides a platform based on Docker virtualization, allowing security researchers and professionals to test and verify their security policies, tools and skills in a controlled environment. This solution may involve the construction, configuration, management and maintenance of the container range to ensure that the range can accurately simulate the required security scenarios and vulnerabilities, thereby providing security personnel with a realistic actual combat exercise environment. In this way, the container range supports the development and testing of security solutions and helps improve the organization's defense capabilities against network security threats.

[0061] It can be seen from the above technical scheme that the present application provides a method for constructing a network range with a multi-layer network structure, and the method can construct a new network range with a multi-layer network structure; the present application greatly reduces the dependence on physical equipment and traditional virtual machines with the help of Docker container technology, and significantly reduces the hardware procurement cost, maintenance cost and energy consumption cost of range construction. In terms of deployment convenience, the containerized deployment method makes the range construction and maintenance process highly simplified, can quickly respond to changes in training needs, and greatly shortens the time cycle from planning to actual use. From the perspective of resource utilization, the application of container technology improves the flexibility and utilization of resource allocation, and can dynamically adjust resource allocation according to different training scenarios, avoiding idleness and waste of resources. In terms of flexibility, the present application can quickly adjust the network structure and container configuration of the range according to the actual training goals and network security research directions, and adapt to the diverse teaching and scientific research needs. In addition, its scalability is also very prominent, it is easy to add new vulnerability environments and attack scenarios (i.e., container instances), it is convenient to update training content in a timely manner, keep up with the development trend of network security technology, and provide network security personnel with an efficient, practical and forward-looking training platform, which has effectively promoted the cultivation and improvement of network security practical capabilities. That is, this application uses Docker containerization, which has fast startup speed and high resource utilization; Docker containerization is easy to adapt to the ICT and has high support for private deployment; it realizes the networking function between containers and supports complex real-world simulation. In other words, this application can target Docker containerization (lightweight, fast startup); support private deployment of ICT; flexible drag-and-drop visualization of target range topology; Docker containerization target range vpc network isolation and security group support, a more secure and isolated network security training environment.

[0062] Specifically, compared with the prior art, the present application has the following advantages:

[0063] Cost-effectiveness: Using container technology reduces dependence on physical devices or virtual machines, thus reducing costs;

[0064] Easy deployment: containerized deployment simplifies the process of setting up and maintaining the shooting range;

[0065] Resource efficiency: Container technology improves resource utilization and isolation;

[0066] Flexibility: The network structure and container configuration of the range can be quickly adjusted as needed;

[0067] Extensibility: easy to add new vulnerability environments and attack scenarios.

[0068] like Figure 2As shown, it is a specific embodiment of a device for constructing a network target range with a multi-layer network structure described in this application. The device described in this embodiment is a physical device for executing the method described in the above embodiment. Its technical solution is essentially consistent with the above embodiment, and the corresponding description in the above embodiment is also applicable to this embodiment. The device described in this embodiment includes:

[0069] The first unit 201 is used to generate a multi-layer network structure range architecture having an internal network, a service network and an external network; wherein the internal network, the service network and the external network in the multi-layer network structure range architecture are all Docker networks; the internal network, the service network and the external network are respectively used to connect different networks;

[0070] The second unit 202 is used to prepare Docker image files corresponding to the internal network, the service network and the external network respectively; wherein the Docker image file corresponding to each network includes a preset type vulnerability environment corresponding to the network, and a service and application program for simulating the preset vulnerability;

[0071] The third unit 203 is used to configure network services for the internal network, the service network and the external network respectively, and set inter-network routing to simulate a real network environment; wherein the network service includes multiple network segments;

[0072] The fourth unit 204 is used to configure corresponding containers and container instances for the internal network, the service network and the external network, respectively, and connect the containers to the networks corresponding thereto; wherein the container instances corresponding to the networks are stored in the containers corresponding to the networks;

[0073] Unit 5 205, for developing a network range management system with the functions of controlling containers to start, stop, monitor and log;

[0074] The sixth unit 206 is used to configure a user interface to obtain a network target range of a target multi-layer network structure; wherein the user interface is used for a user to select different vulnerability scenarios through the user interface and conduct actual combat exercises through the network target range.

[0075] Optionally, the internal network is used to connect to a network for accessing an internal database of an operating system; the service network is used to connect to a network for accessing business services; and the external network is used to connect to a network for connecting to external devices.

[0076] Optionally, the second unit 202 is used to:

[0077] In response to the network security requirements corresponding to the internal network, the service network and the external network, Docker image files corresponding to the internal network, the service network and the external network are generated according to various security vulnerabilities and simulated attack scenarios corresponding to the network security requirements corresponding to the internal network, the service network and the external network.

[0078] Optionally, the Docker image file corresponding to the internal network includes a preset type of vulnerability environment corresponding to the internal network, vulnerabilities of the operating system corresponding to the internal network, and vulnerabilities of basic middleware; the Docker image file corresponding to the service network includes a preset type of vulnerability environment corresponding to the service network and vulnerabilities of business services; the Docker image file corresponding to the external network includes a preset type of vulnerability environment and an access entrance corresponding to the external network.

[0079] Optionally, the third unit 203 is used to:

[0080] Based on the principle of network security isolation, multiple network segments are respectively configured for the internal network, the service network and the external network, and the network segments corresponding to the internal network, the service network and the external network are different.

[0081] Optionally, the monitoring function of the network target range management system is specifically used to monitor the resource usage and operation status of the containers corresponding to the internal network, the service network and the external network; the logging function of the network target range management system is specifically used to record the log records corresponding to the internal network, the service network and the external network, wherein the log records include records of user operations and key events during system operation.

[0082] Optionally, the user interface is further used to: provide an interactive interface, in which different vulnerability scenarios are displayed to facilitate user selection of a vulnerability scenario;

[0083] The device further comprises a seventh unit, configured to:

[0084] In response to a vulnerability scenario selected by a user through the user interface, corresponding container configurations are deployed for containers of the internal network, the service network, and the external network respectively according to the vulnerability scenario selected by the user.

[0085] Optionally, the actual combat drill includes: penetration testing, vulnerability exploitation and defense strategy verification.

[0086] Figure 3It is a structural diagram of an electronic device provided in an embodiment of the present application. At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. Among them, the memory may include a memory, such as a high-speed random access memory (Random-Access Memory, RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage, etc. Of course, the electronic device may also include hardware required for other services.

[0087] The processor, network interface and memory can be interconnected through an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0088] The memory is used to store execution instructions. Specifically, the execution instructions are computer programs that can be executed. The memory may include internal memory and non-volatile memory, and provides execution instructions and data to the processor.

[0089] In one possible implementation, the processor reads the corresponding execution instructions from the non-volatile memory into the memory and then runs them, and can also obtain the corresponding execution instructions from other devices to form a device for constructing a network range with a multi-layer network structure at the logical level. The processor executes the execution instructions stored in the memory to implement the method for constructing a network range with a multi-layer network structure provided in any embodiment of the present application through the executed execution instructions.

[0090] The above application Figure 1The method performed by the device for constructing a network target range with a multi-layer network structure provided in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or instructions in the form of software. The above processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The various methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0091] The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0092] An embodiment of the present application also proposes a readable storage medium, which stores execution instructions. When the stored execution instructions are executed by a processor of an electronic device, the electronic device can execute the method for constructing a network target range with a multi-layer network structure provided in any embodiment of the present application, and is specifically used to execute the method for constructing a network target range with a multi-layer network structure.

[0093] The electronic device described in the above embodiments may be a computer.

[0094] Those skilled in the art should understand that the embodiments of the present application can be provided as methods or computer program products. Therefore, the present application can adopt a complete hardware embodiment, a complete software embodiment, or a combination of software and hardware.

[0095] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0096] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0097] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A method for constructing a network target range with a multi-layer network structure, characterized in that: The method comprises: Generate a multi-layer network structure target range architecture with an internal network, a service network and an external network; wherein the internal network, the service network and the external network in the multi-layer network structure target range architecture are all Docker networks; the internal network, the service network and the external network are respectively used to connect different networks; Creating respective Docker image files for the internal network, the service network, and the external network; wherein the Docker image file corresponding to each network includes a preset type vulnerability environment corresponding to the network, and services and applications for simulating preset vulnerabilities; Configure network services for the internal network, the service network and the external network respectively, and set up inter-network routing to simulate a real network environment; wherein the network service includes multiple network segments; For the internal network, the service network and the external network, respectively configure corresponding containers and container instances, and connect the containers to the networks corresponding thereto; wherein the container instances corresponding to the networks are stored in the containers corresponding to the networks; Develop a network range management system with the ability to control containers for starting, stopping, monitoring, and logging; A user interface is configured to obtain a network target range with a multi-layer network structure; wherein the user interface is used for the user to select different vulnerability scenarios through the user interface and conduct actual combat exercises through the network target range.

2. The method according to claim 1, characterized in that The internal network is used to connect to a network for accessing an internal database of an operating system; the service network is used to connect to a network for accessing business services; and the external network is used to connect to a network for connecting to external devices.

3. According to the method of claim 1, the step of preparing Docker image files corresponding to the internal network, the service network and the external network respectively comprises: In response to the network security requirements corresponding to the internal network, the service network and the external network, Docker image files corresponding to the internal network, the service network and the external network are generated according to various security vulnerabilities and simulated attack scenarios corresponding to the network security requirements corresponding to the internal network, the service network and the external network.

4. The method according to claim 1, characterized in that The Docker image file corresponding to the internal network includes the preset type vulnerability environment corresponding to the internal network, the vulnerabilities of the operating system corresponding to the internal network, and the vulnerabilities of the basic middleware; the Docker image file corresponding to the service network includes the preset type vulnerability environment corresponding to the service network and the vulnerabilities of the business services; the Docker image file corresponding to the external network includes the preset type vulnerability environment and access entry corresponding to the external network.

5. The method according to claim 1, characterized in that: The configuring network services for the internal network, the service network, and the external network respectively includes: Based on the principle of network security isolation, multiple network segments are respectively configured for the internal network, the service network and the external network, and the network segments corresponding to the internal network, the service network and the external network are different.

6. The method according to claim 1, characterized in that The monitoring function of the network range management system is specifically used to monitor the resource usage and operation status of the containers corresponding to the internal network, the service network and the external network; the logging function of the network range management system is specifically used to record the log records corresponding to the internal network, the service network and the external network, wherein the log records include records of user operations and key events during system operation.

7. The method according to claim 1, characterized in that The user interface is also used to: provide an interactive interface, in which different vulnerability scenarios are displayed to facilitate the user to select a vulnerability scenario; The method further comprises: In response to a vulnerability scenario selected by a user through the user interface, corresponding container configurations are deployed for containers of the internal network, the service network, and the external network respectively according to the vulnerability scenario selected by the user.

8. The method according to claim 1, characterized in that The practical exercises include: penetration testing, vulnerability exploitation and defense strategy verification.

9. A device for constructing a network range with a multi-layer network structure, characterized in that: The device comprises: The first unit is used to generate a multi-layer network structure target range architecture having an internal network, a service network and an external network; wherein the internal network, the service network and the external network in the multi-layer network structure target range architecture are all Docker networks; the internal network, the service network and the external network are respectively used to connect different networks; The second unit is used to prepare Docker image files corresponding to the internal network, the service network and the external network respectively; wherein the Docker image file corresponding to each network includes a preset type vulnerability environment corresponding to the network, and a service and application program for simulating the preset vulnerability; The third unit is used to configure network services for the internal network, the service network and the external network respectively, and set inter-network routing to simulate a real network environment; wherein the network service includes multiple network segments; A fourth unit is used to configure corresponding containers and container instances for the internal network, the service network, and the external network, respectively, and connect the containers to the networks corresponding thereto; wherein the container instances corresponding to the networks are stored in the containers corresponding to the networks; Unit 5 is used to develop a network range management system with the ability to control containers for starting, stopping, monitoring, and logging; The sixth unit is used to configure a user interface to obtain a network target range of a target multi-layer network structure; wherein the user interface is used for a user to select different vulnerability scenarios through the user interface and conduct actual combat exercises through the network target range.

10. An electronic device, characterized in that: The electronic device includes a processor and a memory storing execution instructions. When the processor executes the execution instructions stored in the memory, the processor executes the method according to any one of claims 1 to 7.