Network penetration test path planning method and system based on improved A star algorithm
Through the improved A-star algorithm and the estimated cost coefficient of neural network optimization, the problem of low efficiency in existing network penetration test path planning is solved, and more efficient and adaptable path planning is achieved, which can effectively identify and evaluate network security vulnerabilities.
Patent Information
- Application Number
- CN202510268282.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-05-27
AI Technical Summary
The existing network penetration test path planning algorithms have problems such as low efficiency and limited application, which are difficult to adapt to in complex network environments.
The improved A-star algorithm is used to dynamically adjust the search strategy to improve path planning efficiency by combining the actual cost function and heuristic estimate cost function, and using neural network to optimize the estimated cost coefficient.
It improves the efficiency of penetration testing, reduces testing time, enhances adaptability to complex network environments, and can more effectively identify and evaluate security vulnerabilities in network systems.
Smart Images

Figure CN120050111A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and in particular to a network penetration test path planning method and system based on an improved A-star algorithm. Background Art
[0002] Network penetration testing evaluates the security of computer systems, networks, applications, or other information technology infrastructures by simulating the techniques and means of malicious attackers. Traditional penetration testing path planning algorithms are usually based on graph theory and search algorithms, such as the A* algorithm, Dijkstra algorithm, depth-first search (DFS), breadth-first search (BFS), etc. These algorithms are designed with the shortest path, minimum cost, or fastest time in mind. However, they have many limitations. For example, the performance of the A* algorithm is highly dependent on the choice of heuristic function, and if the heuristic is inaccurate, it may lead to suboptimal solutions. In addition, the A* algorithm may be difficult to adapt to complex network environments. The time complexity of the Dijkstra algorithm is relatively high, especially when the network scale is large, the amount of calculation will increase significantly. Moreover, it does not have heuristic capabilities and cannot handle environments with uncertainty. Q-learning and other RL methods require a trade-off between "exploring" new paths and "exploiting" known best paths. This may lead to inefficient search in the early stages because the algorithm must try different actions to understand the environment and update its strategy. The convergence speed of RL algorithms may be slow, especially when the environment is complex or the state space is large. To obtain an effective policy, an RL agent may need to go through an extensive trial-and-error process, which may be unacceptable in real-time applications. Summary of the invention
[0003] To this end, the present invention provides a network penetration test path planning method and system based on an improved A-star algorithm to solve the problems of low efficiency and limited application in existing network penetration test path planning.
[0004] According to the design scheme provided by the present invention, on the one hand, a network penetration test path planning method based on an improved A-star algorithm is provided, comprising:
[0005] Determine the target network and the target nodes in the target network within the scope of the penetration test scenario, and scan to obtain the target network status data, wherein the target network status data includes: network topology information, application service information, vulnerability information and asset information;
[0006] The target node and target network status data are input into the A-star algorithm, and the A-star algorithm is used to search for the optimal path for the target network penetration test. The A-star algorithm adopts an evaluation function composed of an actual cost function from the network starting node to the current node and a heuristic estimated cost function from the current node to the target node, wherein the estimated cost coefficient in the heuristic estimated cost function is the optimal value optimized by the neural network and the optimal value is dynamically adjusted according to the current network information.
[0007] As a network penetration test path planning method based on the improved A-star algorithm of the present invention, further, scanning and obtaining target network status data includes:
[0008] Use scanning tools to map the physical connections and logical structure of the target network, and identify internal and external network boundaries and node devices;
[0009] Determine the type and version of the running application service through port scanning and application service version detection;
[0010] Use vulnerability scanning tools to obtain target network security flaws and generate a vulnerability list;
[0011] The network asset inventory tool is used to record key IT assets and the network locations and relationships of the IT assets. The key IT assets include servers, databases, storage devices, and applications.
[0012] As a network penetration test path planning method based on the improved A-star algorithm of the present invention, further, the evaluation function of the A-star algorithm is expressed as f(n)=g(n)+α(n)·h(n), g(n) is the actual cost function from the initial node point to the current node n, h(n) is the heuristic estimated cost function from the current node n to the target node, and α(n) is the estimated cost coefficient.
[0013] As a network penetration test path planning method based on the improved A-star algorithm of the present invention, further, the step of estimating the cost coefficient to obtain the optimal value through neural network optimization includes:
[0014] Simulate the network topology and generate sample topologies of a specified size and quantity. Use the A-star algorithm to search for paths in each sample topology to obtain training samples. Each training sample contains the actual estimated cost coefficient and the corresponding actual search cost.
[0015] A neural network loss function is set, and the neural network model is trained and learned based on the neural network loss function and using training samples until the model converges, so as to obtain the target neural network model, so as to dynamically adjust the estimated cost coefficient in the A-star algorithm according to the input current network status data.
[0016] As a network penetration test path planning method based on the improved A-star algorithm of the present invention, further, a neural network loss function is set, including:
[0017] The main loss function between the actual estimated cost coefficient and the network output predicted cost coefficient is set using the mean square error function;
[0018] A discriminative loss function is used to encourage the model to distinguish between the actual estimated cost coefficient and the network output predicted cost coefficient using random perturbations and hyperparameter threshold settings;
[0019] The difference between the actual cost functions of the two nodes in the search process and the network output prediction cost coefficient are used to set the monotonic loss function for maintaining the monotonicity of the prediction cost coefficient; and the soft threshold function and the Efficient function are used to set the efficiency optimization loss function;
[0020] The neural network loss function is constructed based on the subject loss function, discrimination loss function, monotonic loss function and efficiency optimization loss function.
[0021] As the network penetration test path planning method based on the improved A-star algorithm of the present invention, further, the neural network loss function is expressed as: L FINAL =λ 1 *L MSE +λ 2 *L dist +λ 3 *L mono +λ 4 *L eff , where λ * is the hyper-parameter weight, L MSE , L dist , L mono , L eff They represent the main loss function, discrimination loss function, monotonic loss function and efficiency optimization loss function respectively.
[0022] As a network penetration test path planning method based on the improved A-star algorithm of the present invention, further, using the A-star algorithm to search and obtain the best path for the target network penetration test includes:
[0023] Construct an open list and a closed list, put the starting network node into the open list and assign an initial cost, the open list is used to store the network nodes to be detected in the path search, the closed list is used to store the network nodes that have been detected in the path search, and the attributes of each network node in the open list and the closed list include: the parent node, the actual cost from the starting node to the current node, the current node estimated cost coefficient dynamically adjusted according to the current network status data, and the estimated cost from the current node to the target node;
[0024] Use the evaluation function to select the node with the smallest cost evaluation from the open list as the current node, and move the current node from the open list to the closed list; for each adjacent node of the current node, check whether the adjacent node is in the closed list; if the adjacent node is not in the open list or the closed list, add the neighbor node to the open list and calculate the actual cost and estimated cost of the adjacent node; if the neighbor node is in the open list, update the actual cost and estimated cost of the neighbor node through the actual cost of the current node to reach the adjacent node, and set the current node as the parent node of the neighbor node;
[0025] The nodes in the open list are sorted by the cost evaluation size to ensure that the current node is selected for path search evaluation next time with the node with the smallest cost evaluation. If the current node is the target node, the path search is successful, and the optimal path from the start node to the target node is rebuilt by backtracking the parent node.
[0026] On the other hand, the present invention also provides a network penetration test path planning system based on the improved A-star algorithm, comprising: a network scanning module and a path planning module, wherein:
[0027] A network scanning module is used to determine the target network and the target nodes in the target network within the scope of the penetration test scenario, and scan to obtain the target network status data, which includes network topology information, application service information, vulnerability information and asset information;
[0028] The path planning module is used to input the target node and target network status data into the A-star algorithm, and use the A-star algorithm to search for the best path for the target network penetration test. The A-star algorithm adopts an evaluation function composed of the actual cost function from the network starting node to the current node and the heuristic estimated cost function from the current node to the target node, wherein the estimated cost coefficient in the heuristic estimated cost function is the optimal value optimized by the neural network and the optimal value is dynamically adjusted according to the current network information.
[0029] Beneficial effects of the present invention:
[0030] The present invention improves the A-star algorithm by integrating a machine learning model to optimize path planning in network penetration testing, improve penetration testing efficiency, reduce test time, and enhance adaptability to complex network environments, thereby more effectively identifying and evaluating security vulnerabilities in network systems, achieving more intelligent and efficient path selection, and being applicable to security assessments of large enterprise networks, cloud computing platforms, and Internet of Things (IoT) devices, and helping security experts quickly locate potential risk points and formulate effective defense strategies. The experimental data verify that the scheme reduces the search time by 32.7% to 51.2% on average in all test cases compared with the traditional A-star algorithm, especially in large networks (more than 500 nodes), the time saving is more significant, reaching about 64.5%; by comparing the actual cost g(n) of the shortest path found, the scheme finds a better or the same path in more than 94.3% of the test cases, indicating that it can effectively improve the path quality; although additional neural network calculations are introduced, since they become very lightweight after training, the overall calculation burden is not significantly increased in practical applications, and the overall calculation resource consumption is reduced due to the improvement of search efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 The figure is a schematic diagram of the network penetration test path planning process based on the improved A-star algorithm in the embodiment. DETAILED DESCRIPTION
[0032] In order to make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and technical solutions.
[0033] In the modern information technology environment, with the increasing complexity of network architecture and the continuous evolution of security threats, traditional penetration testing methods face many challenges. In order to meet these challenges, the embodiments of the present invention refer to Figure 1 As shown, a network penetration test path planning method based on an improved A-star algorithm is provided, comprising:
[0034] S101. Determine a target network and a target node in the target network within the scope of a penetration test scenario, and scan to obtain target network status data, wherein the target network status data includes network topology information, application service information, vulnerability information, and asset information.
[0035] Specifically, scanning and obtaining target network status data may be designed to include:
[0036] Use scanning tools to map the physical connections and logical structure of the target network, and identify internal and external network boundaries and node devices;
[0037] Determine the type and version of the running application service through port scanning and application service version detection;
[0038] Use vulnerability scanning tools to obtain target network security flaws and generate a vulnerability list;
[0039] The network asset inventory tool is used to record key IT assets and the network locations and relationships of the IT assets. The key IT assets include servers, databases, storage devices, and applications.
[0040] Before any path planning, a comprehensive scan of the target network is first required. This phase aims to collect as much information as possible, including but not limited to network topology, open service ports, running applications, possible vulnerabilities, and the location of key assets. To ensure the accuracy and completeness of the data, it is recommended to use mature and proven scanning tools, such as Nmap for network discovery and port scanning, OpenVAS or Nessus for vulnerability assessment, and other specialized security assessment tools. These tools can provide detailed reports to help identify potential entry points and weak links in the network.
[0041] 1) Network topology scanning: Use tools such as Nmap to map the physical and logical structure of the network and identify internal and external network boundaries, routers, switches, and other network devices.
[0042] 2) Service and application identification: Through port scanning and service version detection, the type of running service and its version information are determined, which helps to subsequently determine which services may have known vulnerabilities.
[0043] 3) Vulnerability assessment: Use vulnerability scanning tools (such as OpenVAS, Nessus) to perform in-depth analysis to discover unpatched security flaws in the system and generate a detailed vulnerability list.
[0044] 4) Asset Inventory: Record all important IT assets, including servers, databases, storage devices, applications, etc., and understand their locations and relationships in the network.
[0045] S102. Input the target node and target network status data into the A-star algorithm, and use the A-star algorithm to search for the best path for the target network penetration test. The A-star algorithm adopts an evaluation function composed of an actual cost function from the network starting node to the current node and a heuristic estimated cost function from the current node to the target node, wherein the estimated cost coefficient in the heuristic estimated cost function is an optimal value optimized by a neural network and the optimal value is dynamically adjusted according to the current network information.
[0046] The heuristic function of the traditional A-star algorithm is as follows:
[0047] f(n)=g(n)+h(n)
[0048] Among them, g(n) is the actual cost from the initial point to the current node, and h(n) is the heuristic estimated cost from the current node to the target node. Here, the coefficient in front of the h(n) function is 1, so in the initial stage of the algorithm, the actual cost and the estimated cost are considered equally, and at the end of the algorithm, the weights of the actual cost and the estimated cost are still equal, which is not in line with the actual scenario of penetration testing. In the penetration testing scenario, it is more desirable to consider the estimated cost more at the beginning, so as to reduce unnecessary node traversal, and when approaching the target, consider the actual cost more, so that the search can be more accurate.
[0049] In the scenario of penetration testing, path planning does not only rely on the "shortest path", but also requires more efficient and strategic path selection. Therefore, simply "equally considering the actual cost and the estimated cost" may not meet the needs. Specifically, the requirements are as follows:
[0050] 1. Pay more attention to the estimated cost h(n) in the early stage: In the early stage of penetration testing, attackers often need to search in a large network environment to avoid direct exposure and triggering defense mechanisms. Therefore, giving priority to the heuristic estimated cost h(n) helps to guide the search towards possible attack targets as soon as possible, reduce meaningless traversal, and reduce the risk of being detected. At this time, reducing the focus on the actual cost makes the search more "fast" rather than "precise".
[0051] 2. Pay more attention to the actual cost g(n) when approaching the target: When approaching the target, the attacker needs to consider the path more accurately to avoid taking a suboptimal path due to over-reliance on heuristic estimates. At this time, increasing the weight of the actual cost g(n) can help the algorithm better handle the "details" and find a shortest path with a lower actual cost, thereby avoiding errors or inefficient paths in the final stage.
[0052] The heuristic function of the traditional A-star algorithm can be modified as follows to obtain an f(n) that is more suitable for penetration testing scenarios, as shown below:
[0053] f(n)=g(n)+α(n)·h(n)
[0054] Among them, α(n) is the estimated cost coefficient. A possible α(n) formula is as follows:
[0055]
[0056] Where D is the estimated maximum search depth. When d(n,s) = 0, α(n) = 2, which means that the estimated cost is considered more in the initial stage; when d(n,s) = D, α(n) = 0, which means that the actual cost is considered more when approaching the target.
[0057] The above α(n) formula can indeed meet the actual situation of the penetration test scenario mentioned earlier, that is, it is more desirable to consider the estimated cost more at the beginning, so as to reduce unnecessary node traversal, and when approaching the target, consider the actual cost more to make the search more accurate.
[0058] However, the α(n) formula that meets this characteristic is not unique. For example, we can also define α(n) using the following formula:
[0059]
[0060] Among them, k and β are hyperparameters, and g(n) is the actual cost function of the current node. From this formula, it can be seen that as the search process progresses, the node's g(n) will gradually increase, thereby making the entire α(n) coefficient smaller, which makes the entire f(n) = g(n) + α(n)·h(n) also meet the needs of the penetration testing scenario, that is, it is more desirable to consider the estimated cost more at the beginning, so as to reduce unnecessary node traversal, and when approaching the target, consider the actual cost more to make the search more accurate.
[0061] Therefore, the choice of α(n) is not unique. How to choose a suitable α(n) according to the current network information? To this end, in this embodiment, the representation of α(n) is learned by machine learning.
[0062] The step of obtaining the optimal value of the estimated cost coefficient through neural network optimization can be designed to include:
[0063] Simulate the network topology and generate sample topologies of a specified size and quantity. Use the A-star algorithm to search for paths in each sample topology to obtain training samples. Each training sample contains the actual estimated cost coefficient and the corresponding actual search cost.
[0064] A neural network loss function is set, and the neural network model is trained and learned based on the neural network loss function and using training samples until the model converges, so as to obtain the target neural network model, so as to dynamically adjust the estimated cost coefficient in the A-star algorithm according to the input current network status data.
[0065] In addition to being defined by function display, the α coefficient of the cost function can also be learned through a neural network. In the embodiment of this case, the α coefficient is automatically adjusted according to a large number of data samples through neural network learning to adapt to different search scenarios and needs. This learning process can not only capture complex patterns that are difficult to find with traditional manual parameter adjustment, but also optimize the value of the α coefficient in continuous iterations, making it closer to the optimal solution in practical applications.
[0066] After learning is complete, the neural network model will be solidified into a lightweight computing module that can be easily integrated into the A* algorithm. Although the neural network may require high computing resources during the training phase, once the training is completed, its computational complexity in practical applications is relatively low. This means that in the actual path search process, the neural network's prediction of the α coefficient will not significantly increase the computational burden of the A* algorithm.
[0067] The α coefficient optimized by the neural network can improve the search efficiency of the A* algorithm. In a complex search space, the traditional A* algorithm may encounter the problem of local optimal solutions, resulting in low search efficiency. The α coefficient learned by the neural network can better balance the accuracy and computational cost of the heuristic function, thereby improving the accuracy and success rate of the search while maintaining computational efficiency.
[0068] During the neural network training phase, by changing and adjusting the input seed topology, an arbitrary number of sample topologies with controllable scale can be generated. A* algorithm search is performed on each sample topology to obtain training samples. Each training sample contains α defined by the function and the corresponding actual search cost g(n). The training loss function is defined by multi-task learning, and the model estimated The actual α and g(n) are input into the loss function for gradient backpropagation and parameter update, and the neural network NNA is finally obtained after convergence. In the search phase, g(n) is input into NNA, and the corresponding α calculated by the model is obtained. nna , using α nna Instead of the original α, it can not only improve the search efficiency of the A* algorithm, but also reduce the computational complexity of the algorithm, making it more efficient and reliable in practical applications. Among them, the loss function of the NNA network consists of 4 parts, which are summarized as follows:
[0069] 1) Main loss function L MSE
[0070] This loss function is a standard mean square error, which is used to ensure that the predicted α coefficient is close to the actual α coefficient. The actual α is used as the initial guide to save the cost of training from scratch. The formula of this loss function is as follows:
[0071]
[0072] Where MSE is the mean square error function, α i is the actual α, is the α predicted by the NNA network.
[0073] 2) Discrimination loss function L dist
[0074] This loss function is used to encourage the NNA network to predict something different from the original, so that new coefficients can be explored. The formula of the loss function is as follows:
[0075]
[0076] where α i is the actual α, is the α predicted by the NNA network, δ is the hyperparameter threshold, and β i is a random disturbance from 0 to 1. Greater than δ*β i , the loss value is 0, which means that if the predicted With the actual α i If the difference between is greater than or equal to the threshold, there will be no additional penalty. Less than δ*β i When This means that if the predicted With the actual α i When the difference between the two values is less than the threshold, the loss function will impose a positive penalty on the model, encouraging the model to increase the difference to approach the threshold. This loss function design can effectively encourage the model to increase the predicted value when the difference is below the threshold. With the actual α i , while not imposing additional penalties when the difference reaches or exceeds the threshold.
[0077] 3) Monotone loss function L mono
[0078] This loss function aims to maintain the monotonicity of the α coefficient. Its formula is as follows:
[0079]
[0080] where n i is the i-th node in the search process, n j is the jth node in the search process, g(n i ) represents node n i The actual cost function, g(n j ) represents node n j The actual cost function is is the prediction α of the NNA network for the i-th node, is the prediction α of the NNA network for the jth node. The whole formula encourages when g(n i ) is greater than g(n j )hour, Should be less than And when g(n i ) is less than g(n j )hour, Should be greater than Thus the monotonicity of the NNA network is guaranteed.
[0081] 4) Efficiency optimization loss function L eff
[0082] The entire loss function first uses the Efficient function to estimate the estimated efficiency of the NNA network α at the current step, and then uses a soft threshold S function to decide whether to optimize α based on gradient backpropagation. The loss function formula is as follows:
[0083]
[0084] Where S(x; τ) is a soft threshold function with a value range of 0 to 1, τ is a smoothing coefficient, Efficient is an efficiency function, and threshold is a predefined efficiency threshold. If it is much larger than threshold, the soft threshold function S will be close to 1. If it is much smaller than the threshold, the soft threshold function S will be close to 0. If S is close to 1, the loss function will be Perform optimization based on gradient backpropagation to improve efficiency. If S is close to 1, no optimization is performed.
[0085] By combining these four loss functions through pre-defined weight hyperparameters, the final loss function L is formed FINAL , the formula is as follows:
[0086] L FINAL =λ 1 *L MSE +λ 2 *L dist +λ 3 *L mono +λ 4 *L eff
[0087] Among them, λ * is a predefined hyperparameter weight. Through gradient descent training, L FINALKeep decreasing, so that the neural network NNA will continuously optimize its output α and finally converge.
[0088] Specifically, the A-star algorithm is used to search for the best path for the target network penetration test, which can be designed to include:
[0089] Construct an open list and a closed list, put the starting network node into the open list and assign an initial cost, the open list is used to store the network nodes to be detected in the path search, the closed list is used to store the network nodes that have been detected in the path search, and the attributes of each network node in the open list and the closed list include: the parent node, the actual cost from the starting node to the current node, the current node estimated cost coefficient dynamically adjusted according to the current network status data, and the estimated cost from the current node to the target node;
[0090] Use the evaluation function to select the node with the smallest cost evaluation from the open list as the current node, and move the current node from the open list to the closed list; for each adjacent node of the current node, check whether the adjacent node is in the closed list; if the adjacent node is not in the open list or the closed list, add the neighbor node to the open list and calculate the actual cost and estimated cost of the adjacent node; if the neighbor node is in the open list, update the actual cost and estimated cost of the neighbor node through the actual cost of the current node to reach the adjacent node, and set the current node as the parent node of the neighbor node;
[0091] The nodes in the open list are sorted by the cost evaluation size to ensure that the current node is selected for path search evaluation next time with the node with the smallest cost evaluation. If the current node is the target node, the path search is successful, and the optimal path from the start node to the target node is rebuilt by backtracking the parent node.
[0092] Once the preliminary scan of the target network is completed, the improved A* algorithm in this case solution can be used to plan the penetration test path. By combining the traditional A* search mechanism with machine learning technology, especially making innovative adjustments in the design of heuristic functions, it is particularly suitable for path selection in complex network environments. The specific steps can be described as follows:
[0093] 1) Pre-planning training phase
[0094] This stage is placed before each specific penetration test application. Its purpose is to learn an NNA network through a large number of samples so that after training, it can dynamically generate the optimal α coefficient when planning the specific penetration test path.
[0095] Build a sample library: Create a series of simulated network topology diagrams as training samples. Each sample contains elements such as the connection relationship between nodes, service information, and vulnerability details.
[0096] Initialization parameters: Set the initial α coefficient value, which will affect the weight ratio between the estimated cost h(n) and the actual cost g(n) in the heuristic function.
[0097] Training the neural network: Use the above sample library to train the neural network and optimize its ability to generate the optimal α coefficient. In this process, by minimizing the comprehensive loss function composed of the main loss LMSE, the discrimination loss Ldist, the monotonicity loss Lmono and the efficiency optimization loss Leff, it is ensured that the model can produce the optimal α value that is both expected and exploratory.
[0098] 2) Planning phase after training is completed
[0099] After training, the actual network status is input into the optimized A* algorithm, and the neural network calculates the α coefficient in real time to guide the algorithm to efficiently search for the optimal path. This process automatically considers changes in the current network status and dynamically adjusts the search strategy to avoid falling into the local optimal solution.
[0100] When the path planning is completed, the next step is to implement specific penetration testing activities based on the best path obtained. This stage involves understanding and using the information collected in the early stage to design and execute various attack methods in a targeted manner to verify the security of the network. It should be noted that all actions follow legal authorization and are carried out within the scope of control to ensure that no unnecessary damage is caused to the real business. The penetration testing process can be described as follows:
[0101] Develop an attack plan: Based on the path planning results, carefully plan each step of the attack, clarify the goals and technical routes of each stage. Consider different types of vulnerabilities and defense measures, and choose the most appropriate attack method, such as SQL injection, cross-site scripting (XSS), buffer overflow, etc.
[0102] Execute attack operations: Carry out attack drills strictly according to the predetermined plan, closely monitor the system's response, and adjust tactics in a timely manner. For high-risk operations, a rollback plan should be prepared in advance so that you can quickly restore the original state when problems occur.
[0103] Evaluate the attack effect: After the attack is over, conduct a comprehensive review of the entire process, summarize the successful experiences and shortcomings. Compare the expected results with the actual performance, evaluate the effectiveness of the penetration test, and provide a reference for future security reinforcement.
[0104] Submit report: Finally, organize all relevant information, write a detailed penetration test report, and report the test results to the client or management. The report should include the problems found, potential risks, and improvement suggestions to help the organization take necessary corrective measures and improve the overall information security level.
[0105] Further, based on the above method, an embodiment of the present invention also provides a network penetration test path planning system based on an improved A-star algorithm, comprising: a network scanning module and a path planning module, wherein:
[0106] A network scanning module is used to determine the target network and the target nodes in the target network within the scope of the penetration test scenario, and scan to obtain the target network status data, which includes network topology information, application service information, vulnerability information and asset information;
[0107] The path planning module is used to input the target node and target network status data into the A-star algorithm, and use the A-star algorithm to search for the best path for the target network penetration test. The A-star algorithm adopts an evaluation function composed of the actual cost function from the network starting node to the current node and the heuristic estimated cost function from the current node to the target node, wherein the estimated cost coefficient in the heuristic estimated cost function is the optimal value optimized by the neural network and the optimal value is dynamically adjusted according to the current network information.
[0108] In order to verify the effectiveness of this solution, the following is a further explanation of the solution combined with experimental data:
[0109] 1. Experimental environment
[0110] Hardware configuration: CPU: Intel Xeon E5-2687W v4 (12 cores, 3.0GHz); GPU: NVIDIA TeslaV100 (32GB video memory, CUDA 11.2, used to accelerate neural network training and inference); Memory: 128GB DDR4; Storage: 1TB NVMe SSD; Operating system: Ubuntu 20.04LTS.
[0111] Software tools: Network simulation tool: NS-3 (enable parallel computing module when generating topology); Penetration testing framework: Metasploit v6.1, Nmap 7.92, OpenVAS 20.08; Neural network framework: TensorFlow 2.8 (integrated NVIDIA CUDA deep optimization library); Algorithm implementation: Python 3.9 (front-end logic), C++17 (core A* algorithm optimization).
[0112] Test network settings: Network size: 100, 300, 500 nodes, additional 1000 nodes to verify scalability. Node attributes: Vulnerability distribution, CVE score 4.0-9.8 (high-risk vulnerabilities account for 30%); Service type, HTTP (40%), SSH (25%), FTP (15%), custom protocol (20%); Asset value, low (50%), medium (30%), high (20%). Dynamic changes: simulated firewall rule updates (5 per second), service start and stop (random 10% nodes).
[0113] Comparison benchmark: Traditional A-star algorithm: fixed α = 1, h(n) = Manhattan distance, open list optimized with Fibonacci heap. Dijkstra algorithm: no heuristic, full graph traversal. Q-learning: ε-greedy strategy (ε = 0.2, decay rate 0.99), reward function 1 / (1+g(n))
[0114] 2. Experimental parameters
[0115] Among them, in the improved A-star algorithm parameters, the neural network architecture is: input layer: 32 dimensions (feature input). Hidden layer: 32 (ReLU) → 16 (Dropout 0.3) → 16 (BatchNorm). Output layer: 1 dimension (dynamic alpha coefficient, Sigmoid activation, mapped to the [0.5, 2.5] interval).
[0116] Training configuration: The sample size is 10,000 groups of topologies (mainly 500 nodes), and the enhanced data includes random node failures and link delay jitter. The optimizer uses Adam (lr=1e-4, β1=0.9, β2=0.999). The training round is 50 Epoch (early stopping strategy, 3 rounds of no loss decline are tolerated). The loss function hyperparameters are set to: λ1=0.5 (L_MSE), λ2=0.2 (L_dist), λ3=0.2 (L_mono), λ4=0.1 (Leff).
[0117] Among the traditional algorithm parameters, the h(n) weight of the A-star algorithm is α=1 (fixed), the open list priority queue is a binary heap, the state space of Q-learning is discretized into 1000 intervals, and the experience replay buffer size is 1e5.
[0118] 3. Experimental results
[0119] The comparison of search time is shown in Table 1 below.
[0120] Table 1 (Unit: seconds, mean ± standard deviation)
[0121] Network size Traditional A-star Improved A-star Time saving rate 100 nodes 1.42±1.5 0.95±1.0 33.1% 300 nodes 6.83±5.1 3.98±3.3 41.7% 500 nodes 15.84±9.2 5.62±4.5 64.5% 1000 nodes Timeout (>30) 9.76±7.1 >6.7%
[0122] In the path quality comparison, in 94.3% of cases, the actual cost of the improved A-star algorithm in this solution is ≤ the traditional A-star (62.5% is better, 31.8% is the same). In the hybrid defense scenario, the success rate of the improved A-star algorithm in this solution is 89.1% (traditional A-star is 70.3%), reflecting the anti-interference ability of dynamic α.
[0123] Resource consumption analysis, GPU acceleration: The training phase of the improved A-star algorithm solution in this case solution is shortened from 12 hours (CPU) to 2 hours (Tesla V100). Inference overhead: The neural network of the improved A-star algorithm solution in this case solution takes 0.75ms for a single prediction, and the memory usage increases by only 12% (compared with traditional A-star).
[0124] In other comparisons, compared with Dijkstra: 500 nodes, the improved A-star algorithm in this case is 98.2% faster (traditional A-star is 85.7% faster). Compared with Q-learning: the improved A-star algorithm in this case requires 76% fewer samples to converge, and the path cost is reduced by 23.5%.
[0125] Therefore, the above experimental data show that this solution can find a better path and effectively improve the path quality. In practical applications, it does not increase the overall computing burden. Due to the improvement in search efficiency, the overall computing resource consumption is reduced.
[0126] Unless otherwise specifically stated, the relative steps, numerical expressions and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0127] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0128] The units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation is not considered to be beyond the scope of the present invention.
[0129] Those skilled in the art will appreciate that all or part of the steps in the above method can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a disk or an optical disk. Optionally, all or part of the steps in the above embodiment can also be implemented using one or more integrated circuits, and accordingly, each module / unit in the above embodiment can be implemented in the form of hardware or in the form of software function modules. The present invention is not limited to any specific form of combination of hardware and software.
[0130] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A network penetration test path planning method based on an improved A-star algorithm, characterized in that: Include: Determine the target network and the target nodes in the target network within the scope of the penetration test scenario, and scan to obtain the target network status data, wherein the target network status data includes: network topology information, application service information, vulnerability information and asset information; The target node and target network status data are input into the A-star algorithm, and the A-star algorithm is used to search for the optimal path for the target network penetration test. The A-star algorithm adopts an evaluation function composed of an actual cost function from the network starting node to the current node and a heuristic estimated cost function from the current node to the target node, wherein the estimated cost coefficient in the heuristic estimated cost function is the optimal value optimized by the neural network and the optimal value is dynamically adjusted according to the current network information.
2. The network penetration test path planning method based on the improved A-star algorithm according to claim 1 is characterized in that: Scan and obtain target network status data, including: Use scanning tools to map the physical connections and logical structure of the target network, and identify internal and external network boundaries and node devices; Determine the type and version of the running application service through port scanning and application service version detection; Use vulnerability scanning tools to obtain target network security flaws and generate a vulnerability list; The network asset inventory tool is used to record key IT assets and the network locations and relationships of the IT assets. The key IT assets include servers, databases, storage devices, and applications.
3. The network penetration test path planning method based on the improved A-star algorithm according to claim 1 is characterized in that: The evaluation function of the A-star algorithm is expressed as f(n)=g(n)+α(n)·h(n), where g(n) is the actual cost function from the initial node point to the current node n, h(n) is the heuristic estimated cost function from the current node n to the target node, and α(n) is the estimated cost coefficient.
4. The network penetration test path planning method based on the improved A-star algorithm according to claim 1 or 3 is characterized in that: The steps of estimating the cost coefficient to obtain the optimal value through neural network optimization include: Simulate the network topology and generate sample topologies of a specified size and quantity. Use the A-star algorithm to search for paths in each sample topology to obtain training samples. Each training sample contains the actual estimated cost coefficient and the corresponding actual search cost. A neural network loss function is set, and the neural network model is trained and learned based on the neural network loss function and using training samples until the model converges, so as to obtain the target neural network model, so as to dynamically adjust the estimated cost coefficient in the A-star algorithm according to the input current network status data.
5. The network penetration test path planning method based on the improved A-star algorithm according to claim 4 is characterized in that: Set the neural network loss function, including: The main loss function between the actual estimated cost coefficient and the network output predicted cost coefficient is set using the mean square error function; A discriminative loss function is used to encourage the model to distinguish between the actual estimated cost coefficient and the network output predicted cost coefficient using random perturbations and hyperparameter threshold settings; The difference between the actual cost functions of the two nodes in the search process and the network output prediction cost coefficient are used to set the monotonic loss function for maintaining the monotonicity of the prediction cost coefficient; and the soft threshold function and the Efficient function are used to set the efficiency optimization loss function; The neural network loss function is constructed based on the subject loss function, discrimination loss function, monotonic loss function and efficiency optimization loss function.
6. The network penetration test path planning method based on the improved A-star algorithm according to claim 5 is characterized in that: The neural network loss function is expressed as: L FINAL =λ1*L MSE +λ2*L dist +λ3*L mono +λ4*L eff , where λ * is the hyper-parameter weight, L MSE , L dist , L mono , L eff They represent the main loss function, discrimination loss function, monotonic loss function and efficiency optimization loss function respectively.
7. The network penetration test path planning method based on the improved A-star algorithm according to claim 1 is characterized in that: Use the A-star algorithm to search for the best path for the target network penetration test, including: Construct an open list and a closed list, put the starting network node into the open list and assign an initial cost, the open list is used to store the network nodes to be detected in the path search, the closed list is used to store the network nodes that have been detected in the path search, and the attributes of each network node in the open list and the closed list include: the parent node, the actual cost from the starting node to the current node, the current node estimated cost coefficient dynamically adjusted according to the current network status data, and the estimated cost from the current node to the target node; Use the evaluation function to select the node with the smallest cost evaluation from the open list as the current node, and move the current node from the open list to the closed list; for each adjacent node of the current node, check whether the adjacent node is in the closed list; if the adjacent node is not in the open list or the closed list, add the neighbor node to the open list and calculate the actual cost and estimated cost of the adjacent node; if the neighbor node is in the open list, update the actual cost and estimated cost of the neighbor node through the actual cost of the current node to reach the adjacent node, and set the current node as the parent node of the neighbor node; The nodes in the open list are sorted by the cost evaluation size to ensure that the current node is selected for path search evaluation next time with the node with the smallest cost evaluation. If the current node is the target node, the path search is successful, and the optimal path from the start node to the target node is rebuilt by backtracking the parent node.
8. A network penetration test path planning system based on an improved A-star algorithm, characterized in that: Contains: network scanning module and path planning module, among which, A network scanning module is used to determine the target network and the target nodes in the target network within the scope of the penetration test scenario, and scan to obtain the target network status data, which includes network topology information, application service information, vulnerability information and asset information; The path planning module is used to input the target node and target network status data into the A-star algorithm, and use the A-star algorithm to search for the best path for the target network penetration test. The A-star algorithm adopts an evaluation function composed of the actual cost function from the network starting node to the current node and the heuristic estimated cost function from the current node to the target node, wherein the estimated cost coefficient in the heuristic estimated cost function is the optimal value optimized by the neural network and the optimal value is dynamically adjusted according to the current network information.
9. An electronic device, characterized in that: include: at least one processor, and a memory coupled to the at least one processor; The memory stores a computer program, and the computer program can be executed by the at least one processor to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 7 can be implemented.
Citation Information
Cited By
Test connection path selection method and device and terminal
CN121541033A