IPS detection rate testing method and device based on threat sample and processing equipment
By transforming and batch modifying the preset threat samples, generating different test samples, and batch playback and log checking of the test objects, the problem of inefficiency of the existing IPS detection rate verification scheme is solved, and efficient and low-cost IPS detection rate testing is achieved.
Patent Information
- Application Number
- CN202411202526.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-29
- Publication Date
- 2025-06-24
AI Technical Summary
The existing IPS detection rate verification scheme is inefficient in the execution of large numbers of threat samples, making it difficult to take into account both testing costs and testing efficiency.
By transforming the preset threat samples, batch modifying them to generate different test samples, and batch playback of the test objects, the logs are checked using automated scripts to judge the IPS detection rate.
It realizes the IPS detection rate testing at a low cost and efficient manner, significantly improving the testing efficiency and is suitable for large-scale verification requirements.
Smart Images

Figure CN120200771A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of testing, and particularly to a method, device, and processing equipment for testing the detection rate of an Intrusion Prevention System (IPS) based on threat samples. Background Art
[0002] In a network architecture, for network devices that specifically undertake Intrusion Prevention System (IPS) services or network devices with IPS policies deployed, during specific operations, it involves the verification process of the IPS detection rate. This verification process is easy to understand, aiming to verify the IPS performance of the device, and is reflected by the indicator of the IPS detection rate.
[0003] Currently, the common IPS detection rate verification schemes mainly include two types:
[0004] (1) Using a professional tester for verification, but this method is expensive and has limited resources, making it difficult to meet the needs of large-scale verification;
[0005] (2) Using the collected threat samples for automated testing, and the specific steps are as follows:
[0006] 1. Clear all IPS logs on the device;
[0007] 2. Replay a single threat sample data packet;
[0008] 3. Use an automated script to check whether there is a corresponding log;
[0009] Repeat steps 1 - 3.
[0010] However, when the required number of samples is large (such as more than 1000), the execution efficiency of this method will be significantly reduced, and it usually takes 5 - 6 hours or more to complete the entire testing process.
[0011] It can be seen that the existing IPS detection rate verification schemes have problems in balancing testing cost and testing efficiency. Summary of the Invention
[0012] This application provides a method, device, and processing equipment for testing the detection rate of an IPS based on threat samples. By transforming the preset threat samples, different test samples can be efficiently configured, so that the IPS detection rate testing work of the test object can be promoted at low cost and high efficiency, and has better application value.
[0013] In a first aspect, this application provides a method for testing the detection rate of an IPS based on threat samples, and the method includes:
[0014] When triggering the IPS detection rate test task, obtain the preset threat samples adapted to the IPS detection rate test task. Among them, the threat samples specifically refer to the traffic samples that have been pre-determined to have a threatening nature, and the preset threat samples are specifically PCAP files;
[0015] Batch modify the preset threat samples to obtain different test samples;
[0016] Batch replay different test samples to the test object, so that the test object processes different test samples according to the IPS policy configured by itself;
[0017] Obtain the working log on the test object. Among them, the working log records the events of the threat samples detected by the test object based on the IPS policy;
[0018] Based on the working log, judge the IPS detection rate of the test object.
[0019] Combined with the first aspect of the present application, in the first possible implementation manner of the first aspect of the present application, batch modifying the preset threat samples to obtain different test samples includes:
[0020] Use the Tcprewrite tool or the Scapy library of python as an automated modification tool to batch modify the preset threat samples to obtain different test samples.
[0021] Combined with the first aspect of the present application, in the second possible implementation manner of the first aspect of the present application, batch modifying the preset threat samples to obtain different test samples includes:
[0022] According to the preset IP address modification policy, batch modify the source IP address and destination IP address of the preset threat samples to obtain different test samples.
[0023] Combined with the second possible implementation manner of the first aspect of the present application, in the third possible implementation manner of the first aspect of the present application, batch modifying the source IP address and destination IP address of the preset threat samples to obtain different test samples includes:
[0024] Batch modify the source IP address of the preset threat samples, and start incrementing from the preset specific address during the modification process. The destination IP address remains unchanged, and both IP addresses are presented in the file name to obtain different test samples.
[0025] Combined with the second possible implementation manner of the first aspect of the present application, in the fourth possible implementation manner of the first aspect of the present application, batch modifying the source IP address and destination IP address of the preset threat samples to obtain different test samples includes:
[0026] Batch modify the destination IP addresses of the preset threat samples, increment from the preset specific addresses during the modification process, keep the source IP address unchanged, and present two IP addresses in the file name to obtain different test samples.
[0027] Combined with the second possible implementation manner of the first aspect of the present application, in the fifth possible implementation manner of the first aspect of the present application, based on the work log, judge the IPS detection rate of the test object, including:
[0028] Traverse the content of the work log to determine the threat detection events corresponding to the specific IP address format of the preset IP address modification policy. Among them, the content of the work log also includes threat detection events involved in addition to the IPS detection rate test task;
[0029] Deduplicate the threat detection events to obtain the deduplication result;
[0030] Based on the number of the deduplication result and the number of different test samples, determine the IPS detection rate of the test object, where the IPS detection rate is obtained by the following formula:
[0031] (Number of deduplication results / Number of different test samples) * 100%.
[0032] Combined with the fifth possible implementation manner of the first aspect of the present application, in the sixth possible implementation manner of the first aspect of the present application, the method further includes:
[0033] Extract the samples that are not included in the deduplication result from different test samples;
[0034] Based on the samples that are not included in the deduplication result in different test samples, perform further analysis and optimization for the IPS detection rate test requirements.
[0035] In the second aspect, the present application provides an IPS detection rate test device based on threat samples. The device includes:
[0036] An acquisition unit, configured to acquire a preset threat sample adapted to the IPS detection rate test task when triggering the IPS detection rate test task, where the threat sample specifically refers to a traffic sample pre-determined to have a threat nature, and the preset threat sample is specifically a PCAP file;
[0037] A modification unit, configured to batch modify the preset threat samples to obtain different test samples;
[0038] A playback unit, configured to batch playback different test samples to the test object, so that the test object processes different test samples according to its configured IPS policy;
[0039] An acquisition unit is further configured to acquire the working log on the test object, where the working log records events of threat samples detected by the test object based on the IPS policy;
[0040] A judgment unit is configured to judge the IPS detection rate of the test object based on the working log.
[0041] Combined with the second aspect of the present application, in the first possible implementation manner of the second aspect of the present application, the modification unit is specifically configured to:
[0042] Use the Tcprewrite tool or the Scapy library of python as an automated modification tool to batch modify the preset threat samples to obtain different test samples.
[0043] Combined with the second aspect of the present application, in the second possible implementation manner of the second aspect of the present application, the modification unit is specifically configured to:
[0044] Batch modify the source IP address and destination IP address of the preset threat samples according to the preset IP address modification policy to obtain different test samples.
[0045] Combined with the second possible implementation manner of the second aspect of the present application, in the third possible implementation manner of the second aspect of the present application, the modification unit is specifically configured to:
[0046] Batch modify the source IP address of the preset threat samples, and increment from the preset specific address during the modification process, keep the destination IP address unchanged, and present two IP addresses in the file name to obtain different test samples.
[0047] Combined with the second possible implementation manner of the second aspect of the present application, in the fourth possible implementation manner of the second aspect of the present application, the modification unit is specifically configured to:
[0048] Batch modify the destination IP address of the preset threat samples, and increment from the preset specific address during the modification process, keep the source IP address unchanged, and present two IP addresses in the file name to obtain different test samples.
[0049] Combined with the second possible implementation manner of the second aspect of the present application, in the fifth possible implementation manner of the second aspect of the present application, the judgment unit is specifically configured to:
[0050] Traverse the content of the working log to determine threat detection events corresponding to the specific IP address format of the preset IP address modification policy, where the content of the working log also includes threat detection events involved in addition to the IPS detection rate test task;
[0051] Deduplicate the threat detection events to obtain a deduplication result;
[0052] Determine the IPS detection rate of the test object based on the number of deduplication results and the number of different test samples. Among them, the IPS detection rate is obtained by the following formula:
[0053] (The number of deduplication results / The number of different test samples) * 100%.
[0054] Combined with the fifth possible implementation manner of the second aspect of the present application, in the sixth possible implementation manner of the second aspect of the present application, the device further includes an optimization unit for:
[0055] Extract the samples in different test samples that are not included in the deduplication results;
[0056] Based on the samples in different test samples that are not included in the deduplication results, conduct further analysis and optimization for the IPS detection rate test requirements.
[0057] In a third aspect, the present application provides a processing device, including a processor and a memory. A computer program is stored in the memory. When the processor calls the computer program in the memory, it executes the method provided by the first aspect of the present application or any one of the possible implementation manners of the first aspect of the present application.
[0058] In a fourth aspect, the present application provides a computer-readable storage medium. The computer-readable storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the method provided by the first aspect of the present application or any one of the possible implementation manners of the first aspect of the present application.
[0059] From the above content, the following beneficial effects of the present application can be obtained:
[0060] For the IPS detection rate verification target, when the present application triggers the IPS detection rate test task, it obtains a preset threat sample adapted to the IPS detection rate test task. Among them, the threat sample specifically refers to a traffic sample that is pre-determined to have a threat nature, and the preset threat sample is specifically a PCAP file; batch modify the preset threat sample to obtain different test samples; batch replay different test samples to the test object, so that the test object processes different test samples according to its configured IPS policy; obtain the working log on the test object, where the working log records the events of the threat samples detected by the test object based on the IPS policy; based on the working log, judge the IPS detection rate of the test object. In this processing process, the present application modifies the preset threat sample to efficiently configure different test samples, so as to promote the IPS detection rate test work of the test object at low cost and high efficiency, and has better application value. Description of the Drawings
[0061] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those skilled in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0062] Figure 1 It is a schematic flowchart of a method for testing the IPS detection rate based on threat samples of the present application;
[0063] Figure 2 It is a schematic diagram of a scenario of the present application using the Tcprewrite tool;
[0064] Figure 3 It is a schematic diagram of a scenario of different test samples of the present application;
[0065] Figure 4 It is a schematic diagram of a scenario of the work log of the present application;
[0066] Figure 5 It is a schematic diagram of a scenario of reading the work log of the present application;
[0067] Figure 6 It is a schematic structural diagram of a device for testing the IPS detection rate based on threat samples of the present application;
[0068] Figure 7 It is a schematic structural diagram of a processing device of the present application. Detailed implementation manners
[0069] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0070] In the description and claims of this application and the above-mentioned drawings, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments described here can be implemented in an order other than that shown or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or modules does not necessarily have to be limited to those steps or modules clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products, or devices. In this application, the naming or numbering of steps does not mean that the steps in the method flow must be executed in the chronological / logical order indicated by the naming or numbering. The named or numbered process steps can be changed in the order of execution according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved.
[0071] The division of modules in this application is a logical division. In actual implementation, there may be other division methods. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections between modules can be electrical or other similar forms, which are not limited in this application. And the modules or sub-modules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed to multiple circuit modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this application.
[0072] Before introducing the IPS detection rate test method based on threat samples provided by this application, the background content involved in this application is first introduced.
[0073] The IPS detection rate test method, device, and computer-readable storage medium based on threat samples provided by this application can be applied to a processing device. By transforming preset threat samples, different test samples can be efficiently configured, so that the IPS detection rate test work for the test object can be promoted at low cost and efficiently, and has good application value.
[0074] The IPS detection rate testing method based on threat samples mentioned in this application can be executed by an IPS detection rate testing device based on threat samples, or different types of processing devices such as a server, a physical host, or a user equipment (UE) that integrates the IPS detection rate testing device based on threat samples. Among them, the IPS detection rate testing device based on threat samples can be implemented in a hardware or software manner. The UE can specifically be a terminal device such as a smart phone, a tablet computer, a notebook computer, a desktop computer, or a personal digital assistant (PDA). The processing devices can be set up in the form of a device cluster.
[0075] It can be understood that the processing device that executes the IPS detection rate testing method provided in this application, or rather, the processing device that carries the corresponding application service of the IPS detection rate testing method provided in this application, can be either a device node in the same network architecture as the test object or a device outside the network architecture. This is possible in actual situations. Regarding its specific device type and device deployment form, considering the flexible application requirements in actual situations, it can be flexibly configured according to actual needs. This application does not make specific limitations.
[0076] Next, the IPS detection rate testing method provided in this application will be introduced.
[0077] First, refer to Figure 1 , Figure 1 FIG. shows a schematic flowchart of a process of the IPS detection rate testing method based on threat samples in this application. The IPS detection rate testing method based on threat samples provided in this application may specifically include the following steps S101 to S105:
[0078] Step S101, when triggering an IPS detection rate testing task, obtain a preset threat sample adapted to the IPS detection rate testing task. Among them, the threat sample specifically refers to a traffic sample that is pre-determined to have a threatening nature, and the preset threat sample is specifically a PCAP file;
[0079] It can be understood that for the IPS detection rate testing task of the test object, in specific applications, it can be a task initiated manually, a task sent by other devices, or a task autonomously initiated by the device locally according to a preset task initiation strategy. The specific task initiation form can be configured according to the preset task initiation strategy and can be configured according to actual needs. This application does not make specific limitations.
[0080] For the IPS detection rate test task, the test object for this time can be directly indicated (the test object can be either a network device specifically responsible for the IPS service or a network device with an IPS policy deployed), or the test object for this time can be indirectly indicated. For example, it can be defaulted that the network device newly appearing in the network architecture and involved in the IPS service is the test object for this time. Another example is that the network device involved in the IPS service in the network architecture and the interval from the last test time has reached the verification cycle can be identified as the test object for this time. It is easy to understand that how to indicate the corresponding test object for the IPS detection rate test task is also relatively flexible.
[0081] Triggered by the IPS detection rate test task, the solution of the present application can be triggered to perform a low-cost and efficient IPS detection rate test to meet the verification requirements for the IPS detection rate of the test object.
[0082] For this, in different preset threat samples corresponding to different IPS detection rate test tasks, the preset threat sample adapted to the current IPS detection rate test task can be obtained, that is, a matching process of the preset threat sample is involved. The purpose is to perform batch modification through the matched preset threat sample to obtain different test samples required for the current IPS detection rate test task.
[0083] The threat sample specifically refers to a traffic sample pre-determined to have a threatening nature, that is, a PCAP file (a traffic file in the PCAP file format). Because it has a threatening nature, theoretically, a test object with IPS function should detect / identify it, but in actual situations, there are cases where it cannot be detected / identified, so there is a verification requirement for the IPS detection rate.
[0084] Step S102, batch modify the preset threat sample to obtain different test samples;
[0085] After obtaining the preset threat sample adapted to the current task, the preset threat sample can be batch modified according to the threat sample modification scheme pre-configured in the present application to modify and obtain different test samples with inconsistent contents but retaining the threat characteristics, so that they can be used for subsequent specific tests.
[0086] It can be understood that the modification process of the preset threat sample can be specifically implemented by a corresponding automated processing tool in actual applications. As long as the involved modification logic is configured, the requirements for efficient and high-precision processing can be met.
[0087] As an exemplary embodiment, here, batch modify the source IP address and destination IP address of the preset threat sample to obtain different test samples, which may specifically include:
[0088] Use the Tcprewrite tool or the Scapy library in Python as an automated modification tool to batch modify the source IP address and destination IP address of the preset threat samples to obtain different test samples.
[0089] It can be understood that the embodiments herein show how to implement the modification process involved in this application. Combining with the actual level, an implementation solution that is convenient for application is provided.
[0090] Taking the Tcprewrite tool as an example, in the specific operation, as Figure 2 As shown in a scenario schematic diagram of this application using the tcprewrite tool, it is possible to specify Python to process all PCAP files (preset threat samples) in a specified directory, generate corresponding cache files, and then use the Tcprewrite tool to modify each PCAP file to achieve batch modification of the preset threat samples.
[0091] Of course, it should also be understood that in addition to the ready-made Tcprewrite tool and the Scapy library in Python, other existing automated processing tools can also be used. Or, an automated processing tool improved on the basis of existing automated processing tools can also be used. Or an in-house developed automated processing tool can also be used. These are all possible.
[0092] In addition, as an exemplary embodiment, batch modifying the source IP address and destination IP address of the preset threat samples to obtain different test samples may specifically include:
[0093] According to the preset IP address modification strategy, batch modify the source IP address and destination IP address of the preset threat samples to obtain different test samples.
[0094] It can be seen that in the detailed operation of the solution of this application, it can specifically focus on the IP address. For network traffic (preset threat samples), the five-tuple information carried by the traffic itself will record the source / destination IP address. In this case, this application can achieve the effect of efficiently batch modifying the preset threat samples and retaining their threat nature by batch modifying the IP address in the five-tuple information.
[0095] Among them, it should be understood that the so-called batch modification of the source IP address and destination IP address of the preset threat samples does not necessarily mean that both IP addresses will be modified at the same time. In the specific operation, only one of the two can be modified.
[0096] On this basis, further, as an exemplary embodiment, batch modifying the source IP address and destination IP address of the preset threat samples to obtain different test samples may specifically include:
[0097] Batch modify the source IP addresses of the preset threat samples, and during the modification process, increment from the preset specific address. Keep the destination IP address unchanged, and at the same time present the two IP addresses in the file name to obtain different test samples.
[0098] It can be seen that in the embodiment herein, it is possible to focus only on the source IP addresses of the preset threat samples and perform batch modification. And during the modification process, the modification starts from the preset specific address in an incremental manner. In this way, the operation cost is very low and the processing efficiency is very convenient.
[0099] As an example, corresponding to the dotted decimal of the IP address, the source IP address can be incremented in the manner of 0.0.0.1. Specifically, the initial value of the source IP address can be set to 100.0.0.1 and incremented, while the destination IP address can be set to 192.168.200.1 and remain unchanged.
[0100] It can also be seen in the example herein that for the destination IP address that remains unchanged, its IP address can be not only the original IP address of the preset threat sample, but also an IP address set in real time by the solution of the present application. For the different test samples obtained by batch modification, as long as the destination IP address is the same and has the effect of remaining unchanged.
[0101] For the different test samples obtained by batch modification, their source and destination IP addresses can also be presented in terms of the file name. This helps to more conveniently track / lock directly in the work log on the test object side later, making the subsequent data processing more cost-effective and efficient. Specifically, for the naming setting here, it can also be combined with Figure 3 a schematic diagram of a scenario of different test samples of the present application shown for a more vivid understanding.
[0102] Similarly, it is also possible to focus on modifying the destination IP address. In this regard, as an exemplary embodiment, batch modifying the source IP address and destination IP address of the preset threat sample to obtain different test samples may also include:
[0103] Batch modify the destination IP addresses of the preset threat samples, and during the modification process, increment from the preset specific address. Keep the source IP address unchanged, and at the same time present the two IP addresses in the file name to obtain different test samples.
[0104] It can be understood that the setting here is similar to the previous one, so the specific description will not be expanded here.
[0105] Step S103, batch replay different test samples to the test object, so that the test object processes different test samples according to the IPS policy configured by itself;
[0106] It can be understood that the different test samples obtained previously are a kind of network traffic in themselves. In this way, through traffic playback operations, the test objects can be batch-played back, and the test objects will process these traffic according to the normal traffic processing method. During this process, since the test objects are configured with IPS functions, they will call the IPS policies configured by themselves to process these traffic (different test samples) to detect / identify whether there are threat characteristics. In addition, security response processing after determining threat characteristics is usually involved (how to respond is not the concern of the solution of this application, so no specific elaboration will be made).
[0107] Regarding the traffic playback processing involved here, in detailed operations, specifically, PCAP sending tools such as tcpreplay can be used. The characteristics of the tools involved are similar to the automated processing tools mentioned previously.
[0108] Step S104: Obtain the working day logs on the test object. Among them, the working day logs record the events of the threat samples detected by the test object based on the IPS policy.
[0109] It can be understood that on the test object side, in the project responsible for the IPS function service, the use of working day logs will be involved. Through these working day logs, the detection / identification results of network traffic based on the IPS policy are recorded, that is, whether the network traffic has a threatening nature is recorded. In addition, the corresponding response results can also be recorded.
[0110] The recording work of the working day logs for each piece of network traffic can be understood as an event. The working day logs are usually CSV files (CSV is a kind of spreadsheet file). In the working day logs, each row corresponds to an event, and the corresponding event information will be recorded.
[0111] In this regard, this application can obtain the working day logs on the test object, which record the events of the threat samples detected by the test object based on the IPS policy. Of course, it also records the events of other threatening network traffic detected by the test object based on the IPS policy.
[0112] In addition, in order to ensure in detail that it will not be interfered by the previous working conditions of the test object or to ensure more efficient subsequent processing, before batch-playing back different test samples to the test object, a pre-operation can also be performed, using background commands to clear the working day logs generated previously on the test object.
[0113] Step S105: Based on the working day logs, judge the IPS detection rate of the test object.
[0114] It can be understood that during the process of batch modification of the preset threat samples adapted to the current situation, following the preset threat sample modification scheme, specific naming or specific content will be left (for example, leaving a specific identifier at a specific position in the traffic content), and these characteristics can be directly / indirectly indicated by the work log (the indirect method means that further searching / locating is required, for example, it is necessary to traverse whether a specific identifier is left at a specific position in the traffic content).
[0115] In this way, after obtaining the work log on the test object side, the test samples replayed due to the solution of this application can be locked from it. In this case, the IPS detection rate of the test object can be conveniently judged / determined by combining the test samples replayed to the test object and the test samples detected by the test object.
[0116] Corresponding to the above-mentioned preset threat sample modification mechanism specifically for IP addresses, as an exemplary embodiment here, based on the work log, to judge the IPS detection rate of the test object, it can specifically include:
[0117] Traverse the content of the work log to determine the threat detection events corresponding to the specific IP address format of the preset IP address modification policy, where the content of the work log also includes threat detection events involved in addition to the IPS detection rate test task;
[0118] Deduplicate the threat detection events to obtain the deduplication result;
[0119] Based on the number of the deduplication result and the number of different test samples, determine the IPS detection rate of the test object, where the IPS detection rate is obtained by the following formula:
[0120] (The number of the deduplication result / The number of different test samples) * 100%.
[0121] It can be understood that during the above-mentioned IP address modification process, IP addresses in a specific format (i.e., specific IP address format) may be involved, such as Figure 3 The source IP address in dotted decimal starting with 100 shown.
[0122] In this case, during the process of traversing the threat detection events of different traffic recorded in the work log on the test object side (i.e., including threat detection events involved in other traffic in addition to this IPS detection rate test task), identify / detect the threat detection events with the IP address in this specific format, and identify the events where the test samples replayed in this IPS detection rate test task are detected by the test object as having threats.
[0123] In this way, after filtering out the threat detection events of duplicate test samples, n test samples detected by the test object among the original m test samples played back can be obtained. At this time, the detection rate ((n / m) * 100%) can be conveniently calculated.
[0124] As an example, for the working day log in CSV format downloaded from the test object side, a scenario schematic diagram of the working day log of this application as shown in Figure 4 can be referred to. In this example, the modification of the IP address is specifically to modify the source IP address and increment it (starting from 100.0.0.1 and incrementing). And in actual situations, the malicious features of traffic have directionality (such as from client to server, server to client). Therefore, both the source IP address and the destination IP address in the working day log will contain addresses starting with 100.
[0125] Next, as shown in Figure 5 a scenario schematic diagram of reading the working day log of this application, a script can be used to read the working day log, read all the source and destination IP addresses, and perform deduplication, that is, read all the data in the ips_sip and ips_dip columns, determine whether it starts with 100. (unique IP address format), and remove the destination address 192.168.200.1. The data after deduplication is the data hit this time. At this time, the number of IP addresses contained in the data is the number of test samples detected by the test object.
[0126] For example, if there are 1000 malicious samples in existence / played back, after exporting the log, extracting the source and destination IP addresses, and the number of IP addresses after deduplication (excluding the destination 192.168.200.1) is 900, then the IPS detection rate is 900 / 1000 * 100% = 90%.
[0127] It can be seen that in the processing mechanism here, the determination setting of the IPS detection rate echoes the batch modification of the preset threat samples before, achieving a very convenient and accurate processing effect.
[0128] And it can be understood that after obtaining the IPS detection rate test result of the test object in this IPS detection rate test task, it can be used to evaluate the IPS performance of the test object.
[0129] Regarding this, the IPS detection rate test method based on threat samples of this application may further include:
[0130] Determine the IPS performance of the test object based on the IPS detection rate.
[0131] It can be understood that during the process of determining the IPS performance of the test object, reference to other information related to the IPS performance of the test object may also be involved, rather than being limited to the currently measured IPS detection rate. These involved reference information and the configuration work of the corresponding quantitative formula for IPS performance can actually be flexibly adjusted according to application requirements.
[0132] In addition, in addition to being able to promote the corresponding analysis and processing work of IPS performance based on the IPS detection rate, for test samples not included in the test result of the IPS detection rate, that is, test samples not detected by the test object, this application can also be used as reference data for optimization in view of the IPS detection rate test requirements.
[0133] Correspondingly, as an exemplary embodiment, the IPS detection rate test method based on threat samples in this application may further include:
[0134] Extract samples that are not included in the deduplication result from different test samples;
[0135] Based on the samples that are not included in the deduplication result from different test samples, further analysis and optimization are performed for the IPS detection rate test requirements.
[0136] It can be understood that the analysis and optimization processing involved here can be carried out for the test object targeted by this IPS detection rate test task. For example, it can be used to evaluate the effectiveness of this IPS detection rate or the improvement direction of the IPS performance of the test object. Or, it can also be carried out for the IPS detection rate test work without considering the test object. For example, it can be used to adjust different preset threat samples adapted to different tasks or the batch modification settings for the selected preset threat samples, etc., so as to further strengthen the application effect of the IPS detection rate test processing solution involved in this application.
[0137] Regarding the above solution content, generally speaking, for the IPS detection rate verification target, when this application triggers the IPS detection rate test task, it obtains a preset threat sample adapted to the IPS detection rate test task. Among them, the threat sample specifically refers to a traffic sample that has been pre-determined to have a threatening nature, and the preset threat sample is specifically a PCAP file; batch modify the preset threat sample to obtain different test samples; batch replay different test samples to the test object, so that the test object processes different test samples according to the IPS policy configured by itself; obtain the working log on the test object, where the working log records the events of the threat samples detected by the test object based on the IPS policy; based on the working log, judge the IPS detection rate of the test object. In this processing process, this application modifies the preset threat sample to efficiently configure different test samples, so that the IPS detection rate test work of the test object can be promoted at low cost and efficiently, and has better application value.
[0138] The above is an introduction to the IPS detection rate test method based on threat samples provided by this application. To facilitate better implementation of the IPS detection rate test method based on threat samples provided by this application, this application also provides an IPS detection rate test device based on threat samples from the perspective of functional modules.
[0139] Refer to Figure 6 , Figure 6 FIG. is a schematic structural diagram of an IPS detection rate test device based on threat samples of this application. In this application, the IPS detection rate test device 600 based on threat samples may specifically include the following structure:
[0140] An acquisition unit 601, configured to obtain a preset threat sample adapted to the IPS detection rate test task when triggering the IPS detection rate test task. Among them, the threat sample specifically refers to a traffic sample that has been pre-determined to have a threatening nature, and the preset threat sample is specifically a PCAP file;
[0141] A modification unit 602, configured to batch modify the preset threat sample to obtain different test samples;
[0142] A playback unit 603, configured to batch replay different test samples to the test object, so that the test object processes different test samples according to the IPS policy configured by itself;
[0143] The acquisition unit 601 is further configured to obtain the working log on the test object, where the working log records the events of the threat samples detected by the test object based on the IPS policy;
[0144] A judgment unit 604, configured to judge the IPS detection rate of the test object based on the working log.
[0145] In yet another exemplary embodiment, the modification unit 602 is specifically configured to:
[0146] Use the Tcprewrite tool or the Scapy library of Python as an automated modification tool to batch modify the preset threat samples to obtain different test samples.
[0147] In yet another exemplary embodiment, the modification unit 602 is specifically configured to:
[0148] Batch modify the source IP address and destination IP address of the preset threat samples according to a preset IP address modification policy to obtain different test samples.
[0149] In yet another exemplary embodiment, the modification unit 602 is specifically configured to:
[0150] Batch modify the source IP address of the preset threat samples, and increment from a preset specific address during the modification process. The destination IP address remains unchanged, and both IP addresses are presented in the file name to obtain different test samples.
[0151] In yet another exemplary embodiment, the modification unit 602 is specifically configured to:
[0152] Batch modify the destination IP address of the preset threat samples, and increment from a preset specific address during the modification process. The source IP address remains unchanged, and both IP addresses are presented in the file name to obtain different test samples.
[0153] In yet another exemplary embodiment, the determination unit 604 is specifically configured to:
[0154] Traverse the content of the work log to determine the threat detection events corresponding to the specific IP address format of the preset IP address modification policy. Among them, the content of the work log also includes the threat detection events involved in addition to the IPS detection rate test task;
[0155] Deduplicate the threat detection events to obtain a deduplication result;
[0156] Based on the number of the deduplication result and the number of different test samples, determine the IPS detection rate of the test object, where the IPS detection rate is obtained by the following formula:
[0157] (Number of deduplication results / Number of different test samples) * 100%.
[0158] In yet another exemplary embodiment, the device further includes an optimization unit 605 for:
[0159] Extract the samples that are not included in the deduplication result from different test samples;
[0160] Based on the samples in different test samples that are not included in the deduplication results, further analysis and optimization are carried out for the IPS detection rate test requirements.
[0161] This application also provides a processing device from the perspective of the hardware structure. Refer to Figure 7 , Figure 7 which shows a schematic structural diagram of the processing device of this application. Specifically, the processing device of this application may include a processor 701, a memory 702, and an input / output device 703. When the processor 701 executes the computer program stored in the memory 702, it realizes each step of the IPS detection rate test method based on threat samples in the corresponding embodiment; or, when the processor 701 executes the computer program stored in the memory 702, it realizes the functions of each unit in the corresponding embodiment. The memory 702 is used to store the computer program required for the processor 701 to execute the IPS detection rate test method based on threat samples in the above corresponding embodiment. Figure 1 Correspondingly, when the processor 701 executes the computer program stored in the memory 702, it realizes each step of the IPS detection rate test method based on threat samples in the corresponding embodiment; or, when the processor 701 executes the computer program stored in the memory 702, it realizes the functions of each unit in the corresponding embodiment. Figure 6 The memory 702 is used to store the computer program required for the processor 701 to execute the above Figure 1 corresponding embodiment of the IPS detection rate test method based on threat samples.
[0162] Exemplarily, the computer program can be divided into one or more modules / units. One or more modules / units are stored in the memory 702 and executed by the processor 701 to complete this application. One or more modules / units can be a series of computer program instruction segments that can complete specific functions, and this instruction segment is used to describe the execution process of the computer program in the computer device.
[0163] The processing device may include, but is not limited to, the processor 701, the memory 702, and the input / output device 703. Those skilled in the art can understand that the schematic diagram is only an example of the processing device, and does not constitute a limitation on the processing device. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, the processing device may also include a network access device, a bus, etc. The processor 701, the memory 702, the input / output device 703, etc. are connected through the bus.
[0164] The processor 701 can be a Central Processing Unit (CPU), or can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The processor is the control center of the processing device and connects various parts of the entire device using various interfaces and lines.
[0165] The memory 702 can be used to store computer programs and / or modules. The processor 701 realizes various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 702, and by calling the data stored in the memory 702. The memory 702 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the processing device, etc. In addition, the memory can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices.
[0166] When the processor 701 is used to execute the computer program stored in the memory 702, the following functions can be specifically realized:
[0167] When triggering an IPS detection rate test task, obtain a preset threat sample adapted to the IPS detection rate test task. Among them, the threat sample specifically refers to a traffic sample that has been pre-determined to have a threat nature, and the preset threat sample is specifically a PCAP file;
[0168] Batch modify the preset threat sample to obtain different test samples;
[0169] Batch playback different test samples to the test object, so that the test object processes different test samples according to the IPS policy configured by itself;
[0170] Obtain the working log on the test object. Among them, the working log records events of the threat samples detected by the test object based on the IPS policy.
[0171] Based on the work log, judge the IPS detection rate of the test object.
[0172] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, the specific working processes of the above-described IPS detection rate test device, processing device, and their corresponding units based on threat samples can refer to, for example, Figure 1 the description of the IPS detection rate test method based on threat samples in the corresponding embodiments, and will not be elaborated herein specifically.
[0173] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by controlling relevant hardware through instructions. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0174] Therefore, the present application provides a computer-readable storage medium, in which multiple instructions are stored, and these instructions can be loaded by a processor to execute the steps of the IPS detection rate test method based on threat samples in the present application as Figure 1 described in the corresponding embodiments. For specific operations, reference can be made to, for example, Figure 1 the description of the IPS detection rate test method based on threat samples in the corresponding embodiments, which will not be elaborated herein.
[0175] Among them, the computer-readable storage medium may include: Read Only Memory (ROM), Random Access Memory (RAM), magnetic disk, optical disk, etc.
[0176] Since the instructions stored in the computer-readable storage medium can execute the steps of the IPS detection rate test method based on threat samples in the present application as Figure 1 described in the corresponding embodiments, therefore, the beneficial effects that can be achieved by the IPS detection rate test method based on threat samples in the present application as Figure 1 described in the corresponding embodiments can be realized. For details, refer to the previous description and will not be elaborated herein.
[0177] The above has introduced in detail the IPS detection rate test method, device, processing device, and computer-readable storage medium provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A method for testing IPS detection rate based on threat samples, characterized in that: The method comprises: When the IPS detection rate test task is triggered, a preset threat sample adapted to the IPS detection rate test task is obtained, wherein the threat sample specifically refers to a traffic sample pre-determined to have a threat nature, and the preset threat sample is specifically a PCAP file; Modifying the preset threat samples in batches to obtain different test samples; replaying the different test samples to the test object in batches, so that the test object processes the different test samples according to the IPS policy configured by the test object; Obtaining a work log on the test object, wherein the work log records events of threat samples detected by the test object based on the IPS policy; Based on the work log, the IPS detection rate of the test object is determined.
2. The method according to claim 1, characterized in that The batch modification of the preset threat samples to obtain different test samples includes: The Tcprewrite tool or the Scapy library of Python is used as an automatic modification tool to batch modify the preset threat samples to obtain the different test samples.
3. The method according to claim 1, characterized in that The batch modification of the preset threat samples to obtain different test samples includes: According to the preset IP address modification strategy, the source IP address and the destination IP address of the preset threat samples are modified in batches to obtain the different test samples.
4. The method according to claim 3, characterized in that The batch modification of the preset threat sample source IP address and destination IP address to obtain different test samples includes: The source IP addresses of the preset threat samples are modified in batches, and are incremented from the preset specific address during the modification process, the destination IP address remains unchanged, and two IP addresses are presented in the file name to obtain the different test samples.
5. The method according to claim 3, characterized in that: The batch modification of the source IP address and the destination IP address of the preset threat samples to obtain different test samples includes: The destination IP addresses of the preset threat samples are modified in batches, and are incremented from the preset specific addresses during the modification process, the source IP address remains unchanged, and two IP addresses are presented in the file name to obtain the different test samples.
6. The method according to claim 3, characterized in that Based on the work log, the IPS detection rate of the test object is determined, including: Traversing the contents of the work log to determine whether there is a threat detection event corresponding to the unique IP address format of the preset IP address modification strategy, wherein the contents of the work log also include threat detection events involved in addition to the IPS detection rate test task; Deduplication is performed on the threat detection events to obtain deduplication results; Based on the number of the deduplication results and the number of the different test samples, the IPS detection rate of the test object is determined, wherein the IPS detection rate is obtained using the following formula: (The number of deduplication results / the number of different test samples)*100%.
7. The method according to claim 6, characterized in that The method further comprises: Extracting samples from the different test samples that are not included in the deduplication result; Based on the samples in the different test samples that are not included in the deduplication results, further analysis and optimization are performed according to the IPS detection rate test requirements.
8. An IPS detection rate testing device based on threat samples, characterized in that: The device comprises: An acquisition unit, used for acquiring a preset threat sample adapted to the IPS detection rate test task when the IPS detection rate test task is triggered, wherein the threat sample specifically refers to a traffic sample pre-determined to have a threatening nature, and the preset threat sample is specifically a PCAP file; A modification unit, used for batch modifying the preset threat samples to obtain different test samples; A playback unit, used to batch playback the different test samples to the test object, so that the test object processes the different test samples according to the IPS policy configured by itself; The acquisition unit is further used to acquire a work log on the test object, wherein the work log records an event of a threat sample detected by the test object based on the IPS policy; The judging unit is used to judge the IPS detection rate of the test object based on the work log.
9. A processing device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program, and the processor executes the method according to any one of claims 1 to 7 when calling the computer program in the memory.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the method according to any one of claims 1 to 7.