Attack simulation network validity quantitative evaluation method, device and system based on attack case classification and grading
By dividing the information system into multiple test network segments and giving weight to each network segment and use case, combined with the defense capabilities of protection resources, the problem of inaccurate network security assessment in the existing technology is solved, and a more accurate network security status assessment is achieved.
Patent Information
- Application Number
- CN202510169943.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-07-01
AI Technical Summary
In the prior art, the network security evaluation method only relies on the use case attack test results, and does not consider the differences between different use cases of the system and between attack network areas, resulting in inaccurate evaluation results.
The information system is divided into multiple test network segments. Through the network segment weights of different test network segments and the use case weights of different use cases, the differentiated impacts of different network regions and use cases on the system network security are quantified, and the defense capabilities of the protection resources are evaluated to determine the network security evaluation results of the entire information system.
Improves the accuracy of network security assessment results, takes into account the differentiated impacts between different use cases and between attack network areas, and provides a more accurate network security status assessment.
Smart Images

Figure CN120238335A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular, to a method, device, and system for quantitatively evaluating the effectiveness of an attack simulation network based on attack use case classification and grading. Background Art
[0002] With the continuous increase and complexity of network threats, the network security protection capabilities of enterprise information systems are facing increasing challenges. Attack testing the defense capabilities of the protection resources configured in the information system through use cases to evaluate the network security of the information system has become a necessary means in the process of network security maintenance. However, the above network security evaluation method only relies on the results of use case attack tests and does not consider the differences between different use cases of the system and the differences between attack network regions, resulting in inaccurate network security evaluation results. Summary of the Invention
[0003] The present invention provides a method, device, and system for quantitatively evaluating the effectiveness of an attack simulation network based on attack use case classification and grading, so as to at least solve the problem in the related art that the network security evaluation results are inaccurate because only the results of use case attack tests are relied on and the differences between different use cases of the system and the differences between attack network regions are not considered. The technical solutions of the present invention are as follows:
[0004] According to the first aspect of the embodiments of the present invention, a method for quantitatively evaluating the effectiveness of an attack simulation network based on attack use case classification and grading is provided, which is applied to an information system. The network included in the information system is divided into multiple test network segments; each test network segment includes different protection resources, and the test network segments are associated with use cases in a corresponding manner, and the use cases are used to attack the corresponding test network segments; the protection resources are used to defend against the attacks on the test network segments to which the protection resources belong; the method includes: determining the weight of each network segment of each test network segment, and determining the weight of each use case of each use case in each test network segment, and determining the defense result of each protection resource in each test network segment against the corresponding each use case; the defense result is the defense result generated by the protection resources in the corresponding test network segment when the use case attacks the corresponding test network segment; according to the weight of each use case of each use case corresponding to each test network segment and the corresponding defense result, determining the evaluation result corresponding to the protection resources of each test network segment; based on the weight of each test network segment corresponding to each test network segment, weighting each evaluation result to obtain the network security evaluation result of the information system.
[0005] As an implementation manner, the network segment weights of each test network segment include: when the protections of the protection resources corresponding to each test network segment fail respectively, obtaining each system metric parameter generated when the information system is to be run; determining the network segment weights of each test network segment according to each system metric parameter corresponding to each test network segment; the system metric parameters include one or more of the following: data leakage rate, input data availability rate, instruction controllability rate, privacy protection rate, data accuracy rate, throughput rate, request rate, source IP access rate, system file integrity rate, system file availability rate, data loss rate, and vulnerability utilization rate.
[0006] In another implementation manner, when the protections of the protection resources corresponding to each test network segment fail respectively, obtaining each system metric parameter generated when the information system is to be run, including: sequentially closing the protection resources corresponding to each test network segment, and while closing the protection resources corresponding to each test network segment, running the test environment of the information system based on each use case corresponding to each test network segment to obtain each system metric parameter in the case where the protection of each test network segment fails.
[0007] In another implementation manner, determining the network segment weights of each test network segment according to each system metric parameter corresponding to each test network segment includes: determining the sum of each system metric parameter as the total metric parameter; for any test network segment, determining the ratio of the sum of the system metric parameters of other test network segments except any test network segment to the total metric parameter as the network segment weight of any test network segment.
[0008] In another implementation manner, the defense result of each test network segment includes the interception rates of the corresponding protection resources for each use case; determining the defense results of the protection resources of each test network segment for the corresponding each use case includes: for any use case of each test network segment, determining the interception rate of the protection resources of each test network segment for any use case according to the number of attack times of any use case attacking the corresponding test network segment and the number of successful interception times of the protection resources of the corresponding test network segment intercepting the attack of any use case.
[0009] In another implementation manner, determining the weights of each use case in each test network segment includes: for any test network segment, classifying the multiple use cases corresponding to any test network segment according to the multi-dimensional use case impact factors to determine the impact levels of each use case among the multiple use cases under each dimensional use case impact factor; determining the weights of each use case according to the impact levels of each use case under each dimensional use case impact factor;
[0010] Among them, the multi-dimensional use case impact factors include: the degree of harm of the use case to the performance of system devices in the corresponding test network segment, the difficulty of using the use case, the occurrence probability of the use case actually occurring, and the impact range of the use case.
[0011] In another implementation manner, the multiple test network segments are the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment; the first test network segment represents the network segment formed by the network path from the external network to the internal network boundary, the second test network segment represents the network segment formed by the network path of the host device entering the internal network, the third test network segment represents the network segment formed by the network path from the host device in the internal network to other host devices in the internal network, and the fourth test network segment represents the network segment formed by the network path from the internal network boundary to the external network; the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment correspond to different weights; the sum of the weights of the four weights corresponding to the four test network segments of the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment is 1.
[0012] In another implementation manner, determining the network segment weights of each test network segment includes: when the test network segment is the first test network segment, determining the first weight of the first test network segment as the network segment weight of the test network segment; when the test network segment is the second test network segment, determining the second weight of the second test network segment as the network segment weight of the test network segment; when the test network segment is the third test network segment, determining the third weight of the third test network segment as the network segment weight of the test network segment; when the test network segment is the fourth test network segment, determining the fourth weight of the fourth test network segment as the network segment weight of the test network segment.
[0013] According to the second aspect of the embodiments of the present invention, there is provided an attack simulation network effectiveness quantitative evaluation device based on attack use case classification and grading, which is applied to an information system. The network included in the information system is divided into multiple test network segments; each test network segment includes different protection resources, and the test network segment is associated and set with use cases, and the use cases are used to attack the corresponding test network segment; the protection resources are used to defend against the attacks on the test network segment to which the protection resources belong; the device includes: a determination unit, configured to determine the network segment weights of each test network segment, and determine the use case weights of each use case in each test network segment, and determine the defense results of the protection resources of each test network segment against the corresponding use cases; the defense result is the defense result generated by the protection resources in the corresponding test network segment when the use case attacks the corresponding test network segment; a first evaluation unit, configured to determine the evaluation results corresponding to the protection resources of each test network segment according to the use case weights of each use case corresponding to each test network segment and the corresponding defense results; a second evaluation unit, configured to weight the evaluation results based on the network segment weights corresponding to each test network segment to obtain the network security evaluation result of the information system.
[0014] According to a third aspect of the embodiments of the present invention, an information system is provided, which is configured to execute the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading as described in the first aspect and any possible implementation manner thereof.
[0015] According to a fourth aspect of the embodiments of the present invention, a computer device is provided, including: a processor and a memory for storing processor-executable instructions; wherein, the processor is configured to execute the executable instructions to implement the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading as described in the first aspect and any possible implementation manner thereof.
[0016] According to a fifth aspect of the embodiments of the present invention, an electronic device is provided to implement the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading as described in the first aspect and any possible implementation manner thereof.
[0017] According to a sixth aspect of the embodiments of the present invention, a computer-readable storage medium is provided. Instructions are stored on the computer-readable storage medium. When the instructions in the computer-readable storage medium are executed by the processor of the computer device, the computer device can execute the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading as described in the first aspect and any possible implementation manner thereof.
[0018] According to a seventh aspect of the embodiments of the present application, a computer program product is provided. The computer program product includes computer instructions. When the computer instructions run on the computer device, the computer device executes the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading as described in the above first aspect and any possible implementation manner thereof.
[0019] The technical solutions provided by the embodiments of the present invention at least bring the following beneficial effects: The information system is divided into multiple test network segments, and the different network segment weights of different test network segments are used to quantitatively represent the different impacts of different network regions on the system network security. At the same time, the different use case weights of different use cases are used to quantitatively represent the different impacts of different use cases on the system network security. Based on this, the network defense capabilities of the protection resources of each test network segment are evaluated according to the test network segments, and thus, according to the respective evaluation results corresponding to the protection resources of each test network segment, the network security evaluation result of the entire information system is determined. Moreover, based on considering the differential impacts between the differences between different use cases and the differences between attack network regions, the network security status of the information system is evaluated, improving the accuracy of the network security evaluation result.
[0020] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The accompanying drawings here are incorporated into the description and form a part of this description, showing embodiments consistent with this application, and are used together with the description to explain the principles of this application, and do not constitute an improper limitation of this application.
[0022] Figure 1 It is a schematic diagram of the framework of an information system shown according to an exemplary embodiment;
[0023] Figure 2 It is a flowchart of a method for quantitatively evaluating the effectiveness of an attack simulation network based on attack use case classification and grading shown according to an exemplary embodiment;
[0024] Figure 3 It is a schematic diagram of security level division shown according to an exemplary embodiment;
[0025] Figure 4 It is a schematic diagram of the weight relationship of a test network segment shown according to an exemplary embodiment;
[0026] Figure 5 It is a schematic diagram of the multi-dimensional impact level of use cases shown according to an exemplary embodiment;
[0027] Figure 6 It is a schematic diagram of use case level division shown according to an exemplary embodiment;
[0028] Figure 7 It is a block diagram of a device for quantitatively evaluating the effectiveness of an attack simulation network based on attack use case classification and grading shown according to an exemplary embodiment;
[0029] Figure 8 It is a schematic diagram of an electronic device shown according to an exemplary embodiment. Detailed implementation manners
[0030] In order to enable those of ordinary skill in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings.
[0031] It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.
[0032] Before introducing the attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading provided by the embodiments of the present application in detail, the application scenarios and implementation frameworks involved in the embodiments of the present application will be briefly introduced.
[0033] With the continuous increase and complexity of network threats, the network security protection capabilities of enterprise information systems are facing greater and greater challenges. Attack testing the defense capabilities of the protection resources configured in the information system through use cases to evaluate the network security of the information system has become an essential means in the process of network security maintenance. However, the above-mentioned network effectiveness quantification evaluation method only relies on the results of use case attack tests and does not consider the impacts of the differences between different use cases of the system and the differences between attack network regions, resulting in inaccurate network security evaluation results.
[0034] In some embodiments, the network effectiveness quantification evaluation method usually based on static indicators, such as system configuration inspection or known vulnerability scanning, but these methods cannot accurately reflect the protection capabilities of the system in dynamic attack scenarios. In recent years, it has aimed to detect the vulnerabilities of the protection system by simulating real attack behaviors.
[0035] The related attack simulation evaluation methods lack systematic classification and grading of attack use cases, and the quantification methods of evaluation results are often limited to a single dimension, unable to comprehensively reflect the protection capability level of the target system. Therefore, there is an urgent need for a quantification evaluation method based on attack use case classification and grading to comprehensively quantify the system's response capabilities to different attack scenarios from multiple dimensions.
[0036] To address the above problems, the present application provides an attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading. The information system is divided into multiple test network segments, and the different network segment weights of different test network segments are used to quantitatively represent the differential impacts of different network regions on the network security of the system. At the same time, the different use case weights of different use cases are used to quantitatively represent the differential impacts of different use cases on the network security of the system. Based on this, the network defense capabilities of the protection resources of each test network segment are evaluated according to the test network segments, and thus, according to the respective evaluation results corresponding to the protection resources of each test network segment, the network security evaluation result of the entire information system is determined. Moreover, on the basis of considering the differential impacts between the differences between different use cases and the differences between attack network regions, the network security status of the information system is evaluated, improving the accuracy of the network security evaluation result.
[0037] The attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading provided by the embodiments of the present application can be applied to information systems with network security evaluation functions.
[0038] To facilitate the understanding of the embodiments of this application, the attack simulation network effectiveness quantitative evaluation method based on attack case classification and grading is abbreviated as the "network security evaluation method". The network security evaluation result is also referred to as the network effectiveness quantitative evaluation result.
[0039] As Figure 1 shown, the information system includes multiple test network segments. The multiple test network segments are divided according to the network service areas and / or network paths of the internal network and the external network of the information system. Each test network segment correspondingly includes different protection resources.
[0040] Specifically, the above-mentioned multiple test network segments can be divided into a first test network segment 11, a second test network segment 12, a third test network segment 13, and a fourth test network segment 14. The internal network includes multiple host devices 15.
[0041] Among them, the first test network segment 11 represents the network segment formed by the network path from the external network to the internal network boundary, the second test network segment 12 represents the network segment formed by the network path to the host device in the internal network, the third test network segment 13 represents the network segment formed by the network path from the host device in the internal network to other host devices in the internal network, and the fourth test network segment 14 represents the network segment formed by the network path from the internal network boundary to the external network.
[0042] The above-mentioned first test network segment 11, second test network segment 12, third test network segment 13, and fourth test network segment 14 correspond to different weights. And the sum of the four weights corresponding to the four test network segments of the first test network segment 11, second test network segment 12, third test network segment 13, and fourth test network segment 14 is 1.
[0043] The above-mentioned first test network segment 11 can be the network path in the boundary penetration stage. The goal of the boundary penetration stage is to obtain the access permission of the system behind the firewall or the boundary protection device, so as to enter the internal network.
[0044] In some embodiments, the attacker lures the user to provide login credentials or other sensitive information through phishing emails, fake websites, etc., or tries to crack the user account password through brute force cracking, dictionary attacks, etc., to obtain the access permission of the information system and enter the internal network.
[0045] The protection resource of the first test network segment 11 can be a boundary penetration defense tool (such as Nmap, Nessus), and this boundary penetration defense tool scans the open ports and known vulnerabilities of the information system.
[0046] The second test network segment 12 can be the network path for the Host Penetration phase. The goal of the Host Penetration phase is to obtain full control of the target host and maintain presence in the system as covertly as possible. The Host Penetration phase refers to the process of further attacking and controlling specific hosts (such as servers, workstations) after successfully obtaining access to the internal network.
[0047] The third test network segment 13 can be the network path for the Lateral Movement phase.
[0048] Lateral Movement means that the attacker expands from the already controlled host to other hosts in the same network to obtain access to more information systems and data. The purpose of the Lateral Movement phase is to expand the attack surface across the entire network and gain control of more hosts and sensitive data.
[0049] The fourth test network segment 14 can be the network path for the Abnormal Outbound Connections phase. Abnormal Outbound Connections refer to the situation where, after successfully controlling a host in the internal network, the attacker establishes a connection from the internal network to the external network (such as the Internet) to perform operations such as data theft, command and control (C&C) communication, etc.
[0050] The goal of the Abnormal Outbound Connections phase is to help the attacker achieve their attack goals (such as data theft, information eavesdropping, ransomware operations, etc.) through covert communication channels while avoiding being detected by security devices or system administrators.
[0051] The above four phases describe a standard path that starts from an external attack, gradually penetrates into the internal network, and finally achieves the attack goals. An important part of network security defense work is to identify and defend against attack behaviors in these different phases.
[0052] For ease of understanding, the following specifically introduces the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading provided by this application in combination with the accompanying drawings. The attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading can be applied to the above information system. The network included in this information system is divided into multiple test network segments.
[0053] Figure 2 is a flowchart of an attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading shown according to an exemplary embodiment, as Figure 2 shown, the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading includes the following steps.
[0054] S21. Determine the weight of each network segment for each test network segment, and determine the weight of each test case for each test case in each test network segment, and determine the defense result of each piece of protection resource in each test network segment against the corresponding test case.
[0055] Each test network segment includes different protection resources respectively. The test network segment is associated and set corresponding to the test case, and the test case is used to attack the corresponding test network segment. The protection resource is used to defend against the attack on the test network segment to which the protection resource belongs.
[0056] The defense result is the defense result generated by the protection resource in the corresponding test network segment when the test case attacks the corresponding test network segment.
[0057] Different test network segments correspond to different weights; each test network segment includes different protection resources. The ownership relationship between the protection resource and the test network segment; the corresponding relationship between the protection resource and the test case.
[0058] For any test network segment, based on the interception rate of the protection resource in the test network segment and the influence factor on the test network segment itself and other test network segments after the interception fails, determine the weight of each test network segment.
[0059] This interception rate can characterize the difficulty level of the test network segment being attacked.
[0060] The interception rate can be understood as the success rate of the protection resource in successful protection.
[0061] S22. According to the weight of each test case corresponding to each test network segment and the corresponding defense result, determine the evaluation result corresponding to the protection resource of each test network segment.
[0062] In one implementation, for any test network segment, first determine the weight of any test case among the test cases in the test network segment. Take the sum of the products of the weights of each test case and the defense results of each test case as the evaluation result of the test network segment.
[0063] S23. Based on the network segment weights corresponding to each test network segment, weight each evaluation result to obtain the network security evaluation result of the information system.
[0064] The magnitude of the above network segment weight indicates the degree of network influence of the test network segment on the information system. The larger the network segment weight, the greater the degree of network influence of the test network segment on the information system. The smaller the network segment weight, the smaller the degree of network influence of the test network segment on the information system.
[0065] The magnitude of the above test case weight indicates the degree of network influence of the test case on the information. The larger the test case weight, the greater the degree of network influence of the test case on the information system. The smaller the test case weight, the smaller the degree of network influence of the test case on the information system.
[0066] Classify the protection resources according to the test network segments. Evaluate the network defense capabilities of the protection resources for each test network segment according to the test network segments, so as to determine the network security assessment result of the entire information system based on each evaluation result corresponding to the protection resources of each test network segment.
[0067] In some embodiments, each evaluation result is weighted to obtain a weighted evaluation result. If the weighted evaluation result is greater than a preset weighted threshold, it is determined that the information system is in a safe state and network security indication information is sent; if the weighted evaluation result is less than or equal to the preset weighted threshold, it is determined that the information system is in a risk state and network danger indication information is sent.
[0068] Furthermore, based on this embodiment, each test network segment is also set with a network segment threshold indicating the network security of the test network segment. Compare each evaluation result of each test network with the network segment threshold of the corresponding test network segment. When the evaluation result is greater than the network segment threshold, it is said that the test network segment is safe; when the evaluation result is less than or equal to the network segment threshold, it is said that the test network segment has a greater network risk and is unsafe. Through the above-mentioned segmented comparison method, the network status of different test network segments is determined respectively, so that when maintaining network security, the test network segment with problems can be quickly located.
[0069] Optionally, if the weighted evaluation result belongs to the first preset weighted range, it is determined that the information system is in the first security level; if the weighted evaluation result belongs to the second preset weighted range, it is determined that the information system is in the second security level; if the weighted evaluation result belongs to the third preset weighted range, it is determined that the information system is in the third security level; if the weighted evaluation result belongs to the fourth preset weighted range, it is determined that the information system is in the fourth security level; if the weighted evaluation result belongs to the fifth preset weighted range, it is determined that the information system is in the fifth security level.
[0070] The first preset weighted range is greater than the second preset weighted range; the second preset weighted range is greater than the third preset weighted range; the third preset weighted range is greater than the fourth preset weighted range; the fourth preset weighted range is greater than the fifth preset weighted range.
[0071] The security levels from the first security level to the fifth security level decrease successively.
[0072] Exemplarily, as Figure 3 shown in the chart, use X to represent the weighted evaluation result.
[0073] When 0 ≤ X < 20, it is in the fifth security level, that is, the initial protection ability (level D). It indicates that the security protection measures are in the initial stage, the organization lacks basic protection measures in terms of security protection, the protection ability and protection measures are not effective, and basic network attacks and security threats cannot be detected.
[0074] When 20 ≤ X < 40, it is in the fourth security level, that is, poor protection ability (Level C). It indicates that the security protection measures are relatively weak. The organization has some basic security protection measures, but the overall security protection ability is low, the security policies and mechanisms are imperfect, there are many protection defects, and the protection ability against general security threats is insufficient.
[0075] When 40 ≤ X < 60, it is in the third security level, that is, basic protection ability (Level B). It indicates that it has basic security protection ability. The organization has established certain security protection measures and can cope with common security threats and attacks, but the protection means against general variant and bypass capabilities are insufficient.
[0076] When 60 ≤ X < 80, it is in the second security level, that is, good protection ability (Level A). It indicates that the security protection measures are relatively perfect. The organization has a high maturity in terms of security protection measures and can effectively detect and intercept complex security threats and attacks. The security policies are comprehensive, the mechanisms are sound, and it has good detection and interception capabilities.
[0077] When 80 ≤ X ≤ 100, it is in the first security level, that is, excellent protection ability (Level S). It indicates that the security protection ability is extremely excellent. The organization is at a leading level in terms of security protection, can cope with various high-level security threats, bypass techniques and samples, the security policies are highly mature, it has advanced security technologies and protection strategies, and has the ability to quickly intercept and alarm.
[0078] Through the above implementation manners, the information system is divided into multiple test network segments, so as to quantitatively represent the differential impacts of different network regions on the system network security through the different network segment weights of different test network segments. At the same time, the differential impacts of different test cases on the system network security are quantitatively represented through the different use case weights of different test cases. Based on this, the network defense capabilities of the protection resources of each test network segment are evaluated according to the test network segments, and thus the network security assessment result of the entire information system is determined according to each evaluation result corresponding to the protection resources of each test network segment. At the same time, based on considering the differential impacts between the differences between different test cases and the differences between attack network regions, the network security state of the information system is evaluated, improving the accuracy of the network security assessment result.
[0079] As an implementation manner, the network segment weights of each test network segment include: when the protection resources corresponding to each test network segment fail respectively, obtaining each system index parameter generated when the information system is to be run; determining the network segment weights of each test network segment according to each system index parameter corresponding to each test network segment; the system index parameters include one or more of the following: data leakage rate, input data availability rate, instruction controllability rate, privacy protection rate, data accuracy rate, throughput rate, request rate, source IP access rate, system file integrity rate, system file availability rate, data loss rate, and vulnerability utilization rate.
[0080] Each test network segment in the information system includes multiple host devices respectively.
[0081] The system index parameters also become the performance index parameters of the system. The above system index parameters include the performance index parameters of each host device.
[0082] The system index parameters are performance parameters used to reflect the system performance.
[0083] In this implementation manner, when the protection resources of a single test network segment in each test network segment fail, the information system is run, and the performance index parameters generated during the operation of the information system are obtained, so as to determine the network segment weight of the test network segment with defense failure based on the magnitude of the performance index parameters.
[0084] In one implementation manner, the specific process of determining the system index parameters includes the following steps: sequentially closing the protection resources corresponding to each test network segment, and while closing the corresponding protection resources of each test network segment, running the test environment of the information system based on each use case corresponding to each test network segment, so as to obtain each system index parameter in the case of protection failure of each test network segment.
[0085] Optionally, the specific process of determining the network segment weight includes: determining the sum of each system index parameter as the total index parameter; for any test network segment, determining the ratio of the accumulated sum of the system index parameters of other test network segments except any test network segment to the total index parameter as the network segment weight of any test network segment.
[0086] The multiple test network segments are divided according to the network service areas and network paths of the internal network and external network of the information system.
[0087] In a weight setting manner, corresponding weights are respectively set for each test network segment.
[0088] Exemplarily, the first weight, the second weight, the third weight, and the fourth weight are respectively set for the four test network segments of the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment.
[0089] Specifically, when the test network segment is the first test network segment, the first weight of the first test network segment is determined as the network segment weight of the test network segment.
[0090] When the test network segment is the second test network segment, the second weight of the second test network segment is determined as the network segment weight of the test network segment.
[0091] When the test network segment is the third test network segment, the third weight of the third test network segment is determined as the network segment weight of the test network segment.
[0092] When the test network segment is the fourth test network segment, the fourth weight of the fourth test network segment is determined as the network segment weight of the test network segment.
[0093] Exemplarily, according to the Figure 4 chart shown, the above first weight to fourth weight are set respectively.
[0094] The first weight of the first test network segment, that is, the network segment weight in the boundary breakthrough stage is 0.4. The first weight is evaluated based on the following dimensional characteristics: personnel awareness, boundary firewall, intrusion prevention system (IPS), mail gateway, Web application firewall (WAF), etc.
[0095] The second weight of the second test network segment, that is, the network segment weight in the host penetration stage is 0.3. The second weight is evaluated based on the following dimensional characteristics: endpoint detection and response (EDR), host intrusion detection system (HIDS), antivirus software (AV), etc.
[0096] The third weight of the third test network segment, that is, the network segment weight in the lateral movement stage is 0.2. The third weight is evaluated based on the following dimensional characteristics: network traffic analysis (NTA), traffic monitoring, intrusion prevention system (IPS), etc.
[0097] The fourth weight of the fourth test network segment, that is, the network segment weight in the abnormal external connection stage is 0.1. The fourth weight is evaluated based on the following dimensional characteristics: network traffic analysis (NTA), threat intelligence, data loss prevention (DLP), etc.
[0098] In another weight setting method, according to the system index parameters in the case of the failure of the protection resources of different test network segments, the weight of the test network segment is determined.
[0099] Specifically, when a test network segment includes multiple system index parameters, the average value of the obtained multiple system index parameters or the weighted average value of the multiple system index parameters is determined as the system index parameter for determining the network segment weight of the test network segment. In this way, different index weights are assigned to the system index parameters of different dimension items, and based on this different index weight, the system index parameters of different dimension items are weighted and averaged to obtain the above weighted average value.
[0100] Optionally, the specific process of determining the above defense result includes: for any use case in each test network segment, according to the number of attack times of any use case attacking the corresponding test network segment and the number of successful interception times of the protection resources of the corresponding test network segment intercepting any use case attack, determine the interception rate of the protection resources of each test network segment for any use case.
[0101] Optionally, the specific process of determining the above use case weight includes: for any test network segment, classify the multiple use cases corresponding to any test network segment according to the multi-dimensional use case impact factors to determine the impact level to which each use case among the multiple use cases belongs under each dimension use case impact factor; according to the impact level to which each use case belongs under each dimension use case impact factor, determine the weight of each use case in the any test network segment.
[0102] In one implementation, use cases are divided into different use case levels. Different use case levels correspond to different use case weights; the use case levels correspond one-to-one with the weighted ranges of the impact levels. The sum of the weights of the different use case weights corresponding to each different use case level is 1.
[0103] Based on this implementation, on the basis of determining the impact level weighted value of a use case, the use case weight of this use case is determined in the following manner. First, determine the target impact level weighted range to which the impact level weighted value belongs, and then determine the weight of the target use case level corresponding to the target impact level weighted range as the use case weight of this use case.
[0104] Among them, the larger the impact level weighted value, the lower the corresponding use case level, and the lower the use case level, the larger the use case weight corresponding to this use case level.
[0105] Among them, the multi-dimensional use case impact factors include: the degree of harm of the use case to the system device performance in the corresponding test network segment (i.e., the first dimension use case impact factor), the difficulty of using the use case (i.e., the second dimension use case impact factor), the occurrence probability of the use case actually occurring (i.e., the third dimension use case impact factor), and the impact range of the use case (i.e., the fourth dimension use case impact factor).
[0106] The impact range of the above use case can be measured and determined by using the number of host devices affected in the information system.
[0107] In a specific implementation, the method for determining the use case weight of any one use case is as follows. Different impact weights are set for different dimension use case impact factors, and then the impact weights are weighted with the corresponding grade values of the impact levels to obtain the impact level weighted value. The weight of the target use case level corresponding to the target impact level range to which the impact level weighted value belongs is determined as the use case weight of the use case. The sum of the different impact weights set for different dimension use case impact factors is 1.
[0108] Exemplarily, according to the chart as Figure 5 shown, set the use case weight of any use case respectively. Different impact weights are set for the use case impact factors in different dimensions.
[0109] First, the impact weight corresponding to the harm degree is 0.5. The impact level of the harm degree is divided into four danger levels: when the impact level of the harm degree is in the low-risk level, the level value is 1 / 4; when the impact level of the harm degree is in the medium-risk level, the level value is 2 / 4; when the impact level of the harm degree is in the high-risk level, the level value is 3 / 4; when the impact level of the harm degree is in the severe level, the level value is 4 / 4.
[0110] Second, the impact weight corresponding to the exploitation difficulty is 0.2. When the impact level of the exploitation difficulty is general, the level value is 0; when the impact level of the exploitation difficulty is easy, the level value is 1.
[0111] Third, the impact weight corresponding to the occurrence probability is 0.2. When the impact level of the occurrence probability is general, the level value is 0; when the impact level of the occurrence probability is relatively high, the level value is 1.
[0112] Fourth, the impact weight corresponding to the impact range is 0.1. When the impact level of the impact range is general, the level value is 0; when the impact level of the impact range is large, the level value is 1.
[0113] The above harm level is determined based on the potential impact of a successful attack on the system or business.
[0114] The above exploitation difficulty is determined based on the technical complexity of the technology required to implement the use case attack and the number of resources required.
[0115] The above occurrence probability is determined based on historical data and the current protection status to evaluate the occurrence possibility of the attack.
[0116] The above impact range is determined based on the number of users, systems or business units that the attack may affect.
[0117] As Figure 6 shown in the chart, the use cases are divided into three different use case levels: primary, intermediate and advanced. The impact level weighted values corresponding to primary, intermediate and advanced respectively belong to the first impact level weighted range (greater than 0.7 and less than or equal to 1), the second impact level weighted range (greater than 0.4 and less than or equal to 0.7) and the third impact level weighted range (greater than 0 and less than or equal to 0.4).
[0118] The above-mentioned primary use case represents common attack use cases. The attack methods and malicious samples are usually known and common attack types, with a relatively large scope of influence. The protection system should have the basic ability to defend against these attacks, and the handling priority is higher.
[0119] The above-mentioned intermediate use case represents general variant attack use cases, with some variations or common bypass methods, and the handling priority is medium.
[0120] The above-mentioned advanced use case represents high-ability attack use cases, which are relatively new attack methods, high-difficulty bypass technologies, or relatively new attack samples, and the handling priority is lower than the other two levels.
[0121] Taking multiple test network segments, namely the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment, as examples, the determination process of the above-mentioned network segment weights and use case weights is described as follows.
[0122] In some specific embodiments, first, according to attack characteristics, threat levels, etc., the attack use cases are divided into different categories, and the use cases are graded based on dimensions such as harm level, exploitation difficulty, occurrence probability, and influence scope. The use cases are also called attack use cases.
[0123] Secondly, the attack use case simulation process is divided into four stages: boundary breakthrough, host penetration, lateral movement, and abnormal external connection, and different weights are assigned to the protection capabilities of each stage.
[0124] Thirdly, based on the graded scores of the attack use cases, the protection effect of a single scenario is calculated.
[0125] Finally, the comprehensive protection ability is calculated by weighting the scenario scores of different stages.
[0126] Based on the above implementation manner, the determination process of the above security level results is described as follows in combination with the following formula.
[0127] First, based on Formula 1, the influence level weighted value of each use case is determined.
[0128] P j =Y j1 ×a I +Y j2 ×a2+Y j3 ×a3+Y j4 ×a4
[0129] Formula (1).
[0130] Among them, P j is the influence level weighted value of use case j; Y jI is the level value of the use case j in the use case influence factor of the first dimension; a Iis the weight of the use case impact factor for the first dimension; Y j2 is the level value of the use case j for the use case impact factor in the second dimension; a2 is the weight of the use case impact factor in the second dimension; Y j3 is the level value of the use case j for the use case impact factor in the third dimension; a3 is the weight of the use case impact factor in the third dimension; Y j4 is the level value of the use case j for the use case impact factor in the fourth dimension; a4 is the weight of the use case impact factor in the fourth dimension.
[0131] Secondly, determine the evaluation result of any test network segment based on Formula 2.
[0132]
[0133] Among them, S i is the evaluation result of the test network segment i, L j is the use case weight corresponding to the use case level to which the impact level weighted value of the use case j belongs; E j is the interception rate of the use case j, and there are m use cases in the test network segment i.
[0134] Finally, determine the evaluation weighted result of the entire test network segment based on Formula 3. This evaluation weighted result is used to indicate the network security evaluation result.
[0135]
[0136] Among them, X is the evaluation weighted result, W i is the weight of the test network segment i, and the information system is divided into n test network segments.
[0137] Through the above implementation methods, the network communication security of the industrial control network can be comprehensively evaluated and analyzed from two aspects: device performance and external attacks, objectively and comprehensively evaluate the security of the industrial control network, realize the intelligent analysis and processing of data, improve the reliability of network security analysis, and at the same time improve the efficiency of equipment fault troubleshooting.
[0138] Among them, the process of classifying and grading the use cases for attack simulation is as follows.
[0139] First, classify the use cases according to the attack types (such as SQL injection, XSS attack, ransomware propagation, etc.).
[0140] Second, grade the attack use cases based on multi-dimensional use case impact factors.
[0141] Third, allocate the network segment weights for each stage or each test network segment based on the test network segments in stages.
[0142] To implement the above functions, the attack simulation network effectiveness quantitative evaluation device based on attack case classification and grading includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0143] The embodiment of the present application also provides an Figure 7 attack simulation network effectiveness quantitative evaluation device based on attack case classification and grading as shown, which is applied to an information system. The network included in the information system is divided into multiple test network segments; each test network segment respectively includes different protection resources, and the test network segments are associated and set corresponding to use cases, and the use cases are used to attack the corresponding test network segments; the protection resources are used to defend against the attacks on the test network segments to which the protection resources belong; the device includes: a determination unit 701, a first evaluation unit 702, and a second evaluation unit 703.
[0144] The determination unit 701 is configured to determine the network segment weights of each test network segment, and to determine the use case weights of each use case in each test network segment, and to determine the defense results of the protection resources of each test network segment against the corresponding use cases; the defense result is the defense result generated by the protection resources in the corresponding test network segment when the use case attacks the corresponding test network segment.
[0145] The first evaluation unit 702 is configured to determine the evaluation results corresponding to the protection resources of each test network segment according to the use case weights of each use case corresponding to each test network segment and the corresponding defense results.
[0146] The second evaluation unit 703 is configured to weight each evaluation result based on the network segment weights corresponding to each test network segment to obtain the network security evaluation result of the information system.
[0147] As an implementation manner, the determination unit 701 is specifically configured to: respectively obtain each system index parameter generated when the information system is to be run in the case where the protection of the protection resources corresponding to each test network segment fails respectively; determine the network segment weights of each test network segment according to each system index parameter corresponding to each test network segment; the system index parameters include one or more of the following: data leakage rate, input data availability rate, instruction controllability rate, privacy protection rate, data accuracy rate, throughput rate, request rate, source IP access rate, system file integrity rate, system file availability rate, data loss rate, and vulnerability utilization rate.
[0148] In another implementation manner, the determination unit 701 is specifically configured to: sequentially close the protection resources corresponding to each test network segment, and while closing the protection resources corresponding to each test network segment, based on each use case corresponding to each test network segment, run the test environment of the information system to obtain each system metric parameter in the case of protection failure of each test network segment.
[0149] In another implementation manner, the determination unit 701 is specifically configured to: determine the sum of each system metric parameter as the total metric parameter; for any test network segment, determine the ratio of the accumulated sum of the system metric parameters of other test network segments other than any test network segment to the total metric parameter as the network segment weight of any test network segment.
[0150] In another implementation manner, the determination unit 701 is specifically configured to: for any use case of each test network segment, determine the interception rate of the protection resources of each test network segment for any use case according to the number of attack times of any use case attacking the corresponding test network segment and the number of successful interception times of the protection resources of the corresponding test network segment intercepting any use case attack.
[0151] In another implementation manner, the determination unit 701 is specifically configured to: for any test network segment, classify the multiple use cases corresponding to any test network segment according to the multi-dimensional use case impact factors to determine the impact level to which each use case among the multiple use cases belongs under each dimensional use case impact factor; determine the weight of each use case according to the impact level to which each use case belongs under each dimensional use case impact factor;
[0152] Among them, the multi-dimensional use case impact factors include: the degree of harm of the use case to the performance of system devices in the corresponding test network segment, the difficulty of using the use case, the occurrence probability of the use case actually occurring, and the impact range of the use case.
[0153] In another implementation manner, the multiple test network segments are the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment; the first test network segment represents the network segment formed by the network path from the external network to the internal network boundary, the second test network segment represents the network segment formed by the network path of the host device entering the internal network, the third test network segment represents the network segment formed by the network path from the host device in the internal network to other host devices in the internal network, and the fourth test network segment represents the network segment formed by the network path from the internal network boundary to the external network; the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment correspond to different weights; the sum of the four weights corresponding to the four test network segments of the first test network segment, the second test network segment, the third test network segment, and the fourth test network segment is 1.
[0154] Another implementation method is to determine the network segment weights of each test network segment, including: when the test network segment is the first test network segment, determining the first weight of the first test network segment as the network segment weight of the test network segment; when the test network segment is the second test network segment, determining the second weight of the second test network segment as the network segment weight of the test network segment; when the test network segment is the third test network segment, determining the third weight of the third test network segment as the network segment weight of the test network segment; when the test network segment is the fourth test network segment, determining the fourth weight of the fourth test network segment as the network segment weight of the test network segment.
[0155] Regarding the device in the above embodiments, the specific manners in which each unit module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0156] Figure 8 is a schematic diagram of an electronic device provided by the present application. As Figure 8 , the electronic device 60 may include at least one processor 601 and a memory 603 for storing instructions executable by the processor. Among them, the processor 601 is configured to execute the instructions in the memory 603 to implement the method for quantitatively evaluating the effectiveness of an attack simulation network based on attack use case classification and grading in the following embodiments.
[0157] In addition, the electronic device 60 may further include a communication bus 602, at least one communication interface 604, an input device 606, and an output device 605.
[0158] The processor 601 may be a central processing unit (CPU), a microprocessing unit, an ASIC, or one or more integrated circuits for controlling the execution of the program of the present application solution.
[0159] The communication bus 602 may include a path for transmitting information between the above components.
[0160] The communication interface 604 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.
[0161] The input device 606 is used to receive input signals and the output device 605 is used to output signals.
[0162] The memory 603 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processing unit through a bus. The memory can also be integrated with the processing unit.
[0163] Among them, the memory 603 is used to store the instructions for executing the solution of this application and is controlled by the processor 601 for execution. The processor 601 is used to execute the instructions stored in the memory 603, thereby implementing the functions in the method of this application.
[0164] In a specific implementation, as an embodiment, the processor 601 can include one or more CPUs, such as Figure 8 CPU0 and CPU1 in
[0165] In a specific implementation, as an embodiment, the electronic device 60 can include multiple processors, such as Figure 8 the processor 601 and the processor 607 in
[0166] This electronic device, as shown in Figure 8 includes: a processor 601 and a memory 603 for storing executable instructions of the processor 601; among them, the processor 601 is configured to execute the executable instructions to implement the attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading as in any of the above possible implementation manners. And it can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0167] An embodiment of the present application further provides an electronic device configured to execute the attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading in any of the above possible implementation manners. And it can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0168] An embodiment of the present application further provides a computer-readable storage medium. When the instructions in the computer-readable storage medium are executed by a processor of a control device or an electronic device, the control device or the electronic device can execute the attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading in any of the above possible implementation manners. And it can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0169] An embodiment of the present application further provides a computer program product, including a computer program or instructions. The computer program or instructions are executed by a processor to perform the attack simulation network effectiveness quantification evaluation method based on attack use case classification and grading in any of the above possible implementation manners. And it can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0170] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0171] It should be understood that the present application is not limited to the exact structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A quantitative evaluation method for attack simulation network effectiveness based on attack case classification and grading, characterized in that: Applied to an information system, the network included in the information system is divided into a plurality of test network segments; each test network segment includes different protection resources, the test network segment is associated with a use case and corresponding settings are made, and the use case is used to attack the corresponding test network segment; The protection resource is used to defend against attacks on the test network segment to which the protection resource belongs; The method comprises: Determine each network segment weight of each test network segment, determine each use case weight of each use case in each test network segment, and determine each defense result of the protection resources of each test network segment for each corresponding use case; the defense result is the defense result generated by the protection resources in the corresponding test network segment when the use case attacks the corresponding test network segment; Determine the evaluation results corresponding to the protection resources of each test network segment according to the use case weights of each use case corresponding to each test network segment and the corresponding defense results; Based on the network segment weights corresponding to the various test network segments, the various evaluation results are weighted to obtain a network security evaluation result of the information system.
2. The method according to claim 1, characterized in that The network segment weights of the test network segments include: When the protection resources corresponding to the test network segments fail respectively, obtaining the system indicator parameters generated by the information system when it is running; Determining the network segment weights of the test network segments according to the system indicator parameters corresponding to the test network segments; The system indicator parameters include one or more of the following: data leakage rate, input data availability rate, instruction controllability rate, privacy protection rate, data accuracy rate, throughput rate, request rate, source IP access rate, system file integrity rate, system file availability rate, data loss rate and vulnerability exploitation rate.
3. The method according to claim 2, characterized in that When the protection resources corresponding to the test network segments fail respectively, obtaining the system indicator parameters generated when the information system is to be run respectively includes: The protection resources corresponding to each test network segment are closed in sequence, and while the corresponding protection resources of each test network segment are closed, the test environment of the information system is run based on the use cases corresponding to each test network segment to obtain the system indicator parameters when the protection of each test network segment fails.
4. The method according to claim 3, characterized in that The determining, according to the system indicator parameters corresponding to the test network segments, the network segment weights of the test network segments includes: The sum of the various system indicator parameters is determined as the total indicator parameter; for any test network segment, the ratio of the cumulative sum of the system indicator parameters of other test network segments other than the any test network segment to the total indicator parameter is determined as the network segment weight of the any test network segment.
5. The method according to claim 1, characterized in that The defense result of each test network segment includes each interception rate of the corresponding protection resource for each corresponding use case; the determination of each defense result of each use case corresponding to the protection resource of each test network segment includes: For any use case of each test network segment, determine the interception rate of the protection resources of each test network segment for any use case based on the number of attacks on the test network segment corresponding to the any use case and the number of successful interceptions of the attack of the any use case by the protection resources of the corresponding test network segment.
6. The method according to claim 1, characterized in that Determining the weight of each use case of each use case in each test network segment includes: For any test network segment, multiple use cases corresponding to the any test network segment are classified according to the multi-dimensional use case impact factor to determine the impact level of each use case in the multiple use cases under each dimensional use case impact factor; Determine the weight of each use case according to the impact level of each use case under the use case impact factor of each dimension; Among them, the multi-dimensional use case impact factors include: the degree of harm of the use case to the performance of system equipment in the corresponding test network segment, the difficulty of using the use case, the probability of the use case actually occurring, and the impact range of the use case.
7. The method according to any one of claims 1 to 6, characterized in that The multiple test network segments are a first test network segment, a second test network segment, a third test network segment and a fourth test network segment; the first test network segment represents a network segment formed by a network path from an external network to a boundary of an internal network, the second test network segment represents a network segment formed by a network path of a host device entering the internal network, the third test network segment represents a network segment formed by a network path from a host device in the internal network to other host devices in the internal network, and the fourth test network segment represents a network segment formed by a network path from a boundary of the internal network to an external network; The first test network segment, the second test network segment, the third test network segment and the fourth test network segment correspond to different weights; The sum of the four weights corresponding to the first test network segment, the second test network segment, the third test network segment and the fourth test network segment is 1.
8. The method according to claim 7, characterized in that Determining the weight of each network segment of each test network segment includes: When the test network segment is the first test network segment, determining the first weight of the first test network segment as the network segment weight of the test network segment; When the test network segment is the second test network segment, determining the second weight of the second test network segment as the network segment weight of the test network segment; When the test network segment is the third test network segment, determining the third weight of the third test network segment as the network segment weight of the test network segment; When the test network segment is the fourth test network segment, the fourth weight of the fourth test network segment is determined as the network segment weight of the test network segment.
9. A device for quantitatively evaluating the effectiveness of an attack simulation network based on attack case classification and grading, characterized in that: The device includes: applied to an information system, the network included in the information system is divided into a plurality of test network segments; each test network segment includes different protection resources, the test network segment is associated with a use case and correspondingly set, and the use case is used to attack the corresponding test network segment; the protection resource is used to defend against attacks on the test network segment to which the protection resource belongs; the device includes: A determination unit, used to determine each network segment weight of each test network segment, and to determine each use case weight of each use case in each test network segment, and to determine each defense result of the protection resources of each test network segment for each corresponding use case; the defense result is the defense result generated by the protection resources in the corresponding test network segment when the use case attacks the corresponding test network segment; A first evaluation unit, configured to determine evaluation results corresponding to protection resources of each test network segment according to each use case weight and each corresponding defense result of each use case corresponding to each test network segment; The second evaluation unit is used to weight the various evaluation results based on the network segment weights corresponding to the various test network segments to obtain the network security evaluation result of the information system.
10. An information system, characterized in that: The network included in the information system is divided into a plurality of test network segments; each test network segment includes different protection resources, and the test network segment is associated with a use case and is set accordingly; The use case is used to attack the corresponding test network segment; the protection resource is used to defend against attacks on the test network segment to which the protection resource belongs; and is configured to execute the attack simulation network effectiveness quantitative evaluation method based on attack use case classification and grading as described in any one of claims 1-8.