Dynamic Evolution of Password Training Range System and Method for Generating Password Training Scenarios
By dynamically generating scene parameters and vulnerability chains, the problem that traditional cryptographic training range systems cannot simulate real business evolution and multi-vulnerability collaboration is solved, and a high-complex training scenario is achieved, which improves training effect and continuity.
Patent Information
- Application Number
- CN202510749529.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-06-06
AI Technical Summary
The traditional cryptographic training range system cannot simulate the dynamic evolution of password configuration in real business, cannot reflect the complexity of the synergy between multiple vulnerabilities in the real attack chain, and it is difficult to flexibly adjust parameters according to the preset model, resulting in a far different training scenario from the actual situation.
It provides a dynamically evolved cryptographic training range system, including scene generation module, vulnerability deduction module, basic service module and feedback control module. By dynamically generating scene parameters, generating vulnerability chains based on vulnerability association knowledge graphs, monitoring the trigger status parameters of vulnerability mirrors, driving the adjustment of scene parameters and the update of vulnerability chains.
It has achieved a leap from a static shooting range to a dynamically evolved shooting range, significantly improving the complexity and training value of the shooting range scene, providing a highly realistic attack scene experience, and ensuring the continuity of password training.
Smart Images

Figure CN120263566B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of cryptographic training ranges, and in particular to a dynamically evolving cryptographic training range system and a cryptographic training scenario generation method. Background Art
[0002] Traditional cryptography training range systems suffer from the following flaws: Simulation scenarios rely on fixed image splicing, failing to simulate the dynamic evolution of cryptography configurations in real-world applications (such as changes in key rotation cycles and protocol version upgrades). Vulnerability images are deployed in isolation, failing to capture the complexities of multiple vulnerabilities working together in a real-world attack chain (for example, permission vulnerabilities require a combination of configuration errors to be exploited).
[0003] Most training scenarios lack the flexibility to adjust parameters based on pre-set models, and the difficulty of the scenarios cannot be precisely controlled. In existing training environments, it's difficult to generate vulnerability chains that conform to the principles of real-world penetration testing based on knowledge graphs and scenario parameters. Factors such as vulnerability correlations, triggering conditions, and algorithm security cannot be fully considered. As a result, the vulnerability scenarios in training differ significantly from reality and fail to provide a realistic attack scenario experience.
[0004] For example, a Chinese patent with authorization announcement number CN116599770B discloses an operating method for an industrial Internet commercial cryptography application training platform, which includes: a training scenario simulating an attacker attacking a risk point, displaying the result of a successful attack, and encrypting data using various commercial cryptography codes to protect against attacks, thereby protecting the data from tampering, theft, and other adverse effects. This technical solution simulates the operation training scenario and has no impact on the actual scenario, thereby avoiding affecting actual production. At the same time, it facilitates personnel to understand commercial cryptography technology based on the training scenario. However, the problem raised in the background technology of this application still exists: it cannot reflect the complexity of the synergistic effect of multiple vulnerabilities in a real attack chain.
[0005] The information disclosed in this background technology section is only intended to enhance the understanding of the overall background of the application and should not be regarded as an admission or any form of suggestion that the information constitutes the prior art already known to ordinary technicians in this field. Summary of the Invention
[0006] The technical problem to be solved by this application is to overcome the defects of the existing technology, provide a dynamically evolving cryptographic training range system and a cryptographic training scenario generation method, realize the transition from a static range to a dynamically evolving range, and improve the complexity of the range scenario and the training value.
[0007] To solve the above technical problems, this application provides the following technical solutions:
[0008] On the one hand, the present application provides a dynamically evolving cryptography training range system, including a scenario generation module, a vulnerability deduction module, a basic service module, and a feedback control module; wherein:
[0009] The scenario generation module is used to dynamically generate scenario parameters and generate a simulation application image based on the scenario parameters;
[0010] The vulnerability deduction module generates a vulnerability chain based on the pre-set vulnerability association knowledge graph and the scenario parameters, and encapsulates the vulnerabilities contained in the vulnerability chain into a vulnerability image and transmits it to the scenario generation module; the scenario generation module integrates the vulnerability image into the simulation application image to generate a composite image;
[0011] The basic service module deploys a network environment based on the network requirements of the vulnerability chain and binds the composite image to the network environment to form a scenario instance;
[0012] The feedback control module is used to monitor the trigger state parameters of the vulnerability image; the feedback control module also drives the adjustment of the scenario parameters based on the trigger state parameters, and drives the update of the vulnerability chain based on the adjustment of the scenario parameters.
[0013] As a preferred solution of the dynamically evolving cryptographic training range system described in the present application, the scenario generation module includes a parameter configuration unit; the parameter configuration unit is used to dynamically generate scenario parameters; the scenario parameters include the cryptographic algorithm version, protocol type, and key length; the dynamic generation of scenario parameters specifically includes: periodically switching the cryptographic algorithm version, protocol type, and key length based on a preset state transition model;
[0014] The state transition model includes a state space and a transition probability matrix; wherein the state space includes a set of values of the cryptographic algorithm version, protocol type, and key length; the transition probability matrix is used to calculate the transition probability of switching the current state space to any state space;
[0015] The parameter configuration unit is configured with a parameter change cycle; at the beginning of each parameter change cycle, the parameter configuration unit switches the current state space to the state space with the maximum transition probability based on the transition probability matrix, thereby realizing dynamic generation of scene parameters.
[0016] As a preferred solution of the dynamically evolving cryptography training range system described in the present application, the scenario generation module further includes an image generation unit; the image generation unit generates a simulation application image based on the scenario parameters, specifically including:
[0017] Load the preset container construction template; inject the current cryptographic algorithm version, protocol type, and key length into the container construction template to generate a container construction instruction; call the container construction tool based on the container construction instruction to generate a simulation application image.
[0018] As a preferred solution of the dynamically evolving cryptography training range system described in the present application, wherein: the vulnerability deduction module includes a knowledge graph unit; the knowledge graph unit is configured with a vulnerability-related knowledge graph; the vulnerability-related knowledge graph includes entity nodes and relationship edges; the entity nodes include vulnerability nodes, protocol type nodes, and cryptographic algorithm nodes; the relationship edges include reachability edges, protocol dependency edges, and algorithm weakening edges;
[0019] The vulnerability nodes are connected by the reachability edge; the reachability edge is used to indicate the possibility of lateral movement of vulnerability exploitation; the vulnerability node and the protocol type node are connected by the protocol dependency edge; the protocol dependency edge is used to identify the protocol environment required for vulnerability triggering; the vulnerability node and the cryptographic algorithm node are connected by the algorithm weakening edge; the algorithm weakening edge is used to associate the algorithm defect with the cause of the vulnerability.
[0020] As a preferred solution of the dynamically evolving cryptography training range system described in this application, the vulnerability deduction module further includes a deduction engine unit; the deduction engine unit is used to generate a vulnerability chain, specifically including:
[0021] Parse the current scenario parameters and read the current cryptographic algorithm version, protocol type, and key length;
[0022] Prune the vulnerability-related knowledge graph based on the current cryptographic algorithm version, protocol type, and key length to obtain the vulnerability chain;
[0023] The vulnerability nodes in the vulnerability chain are encapsulated into vulnerability images that can be started and stopped independently, and the network service port mapping relationship is retained between the vulnerability images corresponding to adjacent vulnerability nodes.
[0024] As a preferred solution of the dynamically evolving cryptography training range system described in this application, the pruning of the vulnerability-related knowledge graph specifically includes:
[0025] Filter cryptographic algorithm nodes based on the cryptographic algorithm version; mark cryptographic algorithm nodes that do not conform to the current cryptographic algorithm version as illegal nodes;
[0026] Filter protocol type nodes based on protocol type; mark protocol type nodes that do not conform to the current protocol type as illegal nodes;
[0027] Remove vulnerability nodes connected to illegal nodes in the vulnerability association knowledge graph.
[0028] As a preferred solution of the dynamically evolving cryptography training range system described in this application, the pruning of the vulnerability-related knowledge graph further includes:
[0029] Based on the key length, a weight value is assigned to the algorithm weakening edge of each vulnerability node in the vulnerability association knowledge graph; specifically, the weight mapping table between key length and cryptographic algorithm type is preset; based on the weight mapping table, the weight of each cryptographic algorithm type under the current key length is queried; based on the weight of the cryptographic algorithm type corresponding to the cryptographic algorithm node connected to the vulnerability node, a weight value is assigned to the algorithm weakening edge;
[0030] A weight threshold interval is preset; vulnerability nodes connected by algorithm-weakened edges whose weight values are not within the weight threshold interval are removed from the vulnerability-related knowledge graph.
[0031] As a preferred solution of the dynamically evolving cryptographic training range system described in the present application, wherein: the vulnerability deduction module includes a vulnerability mirror unit;
[0032] The vulnerability image unit is used to encapsulate the vulnerability image and transmit the vulnerability image to the image generation unit; the image generation unit integrates the vulnerability image into the simulation application image to generate a composite image, specifically including: layering and merging the vulnerability image and the simulation application image to generate a composite image containing the trigger environment of each vulnerability image.
[0033] As a preferred solution of the dynamically evolving cryptography training range system described in the present application, wherein: the basic service module includes a network configuration unit; the network configuration unit deploys a network environment based on the network requirements of the vulnerability chain; the network requirements of the vulnerability chain include a protocol communication matrix, topology constraints for triggering vulnerabilities in the vulnerability chain, and access control rules for vulnerabilities in the vulnerability chain; the protocol communication matrix is used to record the network protocol type and port number range required to trigger each vulnerability in the vulnerability chain;
[0034] The network configuration unit is further used to bind the composite image to the network environment to form a scenario instance.
[0035] As an optimal solution for a dynamically evolving cryptographic training range system described in the present application, the feedback control module includes a vulnerability monitoring unit and a control instruction unit; the vulnerability monitoring unit is used to monitor the trigger status parameters of the vulnerability image; the trigger status parameters include the trigger identifier of the vulnerability image; the trigger identifier of the vulnerability image is used to mark whether the corresponding vulnerability image is successfully triggered.
[0036] The control instruction unit drives the adjustment of the scene parameters based on the trigger state parameters, specifically including:
[0037] The triggering success rate of the vulnerability image and the number of vulnerability triggering times are calculated based on the triggering identifier of the vulnerability image; the switching frequency of the cryptographic algorithm version is adjusted based on the triggering success rate of the vulnerability image; and the key length is adjusted based on the number of vulnerability triggering times.
[0038] As a preferred solution of the dynamically evolving cryptography training range system described in this application, the control instruction unit further drives the update of the vulnerability chain based on the adjustment of scenario parameters, specifically including:
[0039] The control instruction unit sends an update instruction to the deduction engine unit; the deduction engine unit responds to the update instruction, parses the current scenario parameters and generates a new vulnerability chain; the vulnerability mirror unit encapsulates the newly added vulnerability image based on the new vulnerability chain; the scenario generation module injects the newly added vulnerability image into the running scenario instance and migrates the historical status data of the triggered vulnerability image to the newly added vulnerability image.
[0040] In a second aspect, the present application provides a method for generating a dynamically evolving cryptographic training scenario, comprising the following steps: dynamically generating scenario parameters based on a preset state transition model;
[0041] Based on the scenario parameters, generating a simulation application image;
[0042] Generate a vulnerability image based on the scenario parameters and a preset vulnerability association knowledge graph;
[0043] Generate a composite image based on the simulated application image and the vulnerability image;
[0044] Deploy a network environment and bind the composite image to the network environment to form a scenario instance;
[0045] Monitor trigger state parameters of the vulnerability image; and drive the adjustment of scenario parameters and the update of scenario instances based on the trigger state parameters.
[0046] Compared with the prior art, the beneficial effects achieved by this application are as follows:
[0047] This application achieves a leap from a static range to a dynamically evolving range through dynamic scenario generation and vulnerability chain deduction. Compared to traditional technologies that focus on a single dimension (such as dynamic configuration or vulnerability library expansion), this solution significantly increases the complexity and training value of the range scenarios.
[0048] This application generates a vulnerability chain based on the vulnerability-related knowledge graph and scenario parameters, prunes and filters the knowledge graph, comprehensively considers multiple factors to quantitatively filter vulnerability nodes, and constructs a vulnerability chain that conforms to the rules of real penetration testing. It reflects the complexity of the coordinated effects of multiple vulnerabilities in the real attack chain and provides highly realistic attack scenarios for practical training.
[0049] By monitoring the vulnerability image trigger status parameters, dynamically adjusting the scenario parameters and driving the vulnerability chain update, the continuity of cryptographic training is ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present application. Those skilled in the art can also derive other drawings based on these drawings without inventive effort. Among them:
[0051] Figure 1 A schematic diagram of the structure of a dynamically evolving cryptography training range system provided in this application;
[0052] Figure 2 A flowchart of a method for generating a dynamically evolving cryptographic training scenario provided in this application. DETAILED DESCRIPTION
[0053] The technical solution of the present application is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. Unless there is a conflict, the embodiments of the present application and the technical features in the embodiments can be combined with each other.
[0054] Example 1
[0055] This embodiment introduces a dynamically evolving password training range system. Figure 1 The system includes a scenario generation module, a vulnerability deduction module, a basic service module, and a feedback control module; wherein:
[0056] The scenario generation module is used to dynamically generate scenario parameters and generate a simulation application image based on the scenario parameters;
[0057] The scenario generation module includes a parameter configuration unit and an image generation unit; wherein the parameter configuration unit is used to dynamically generate scenario parameters; the scenario parameters include a cryptographic algorithm version, a protocol type, and a key length; the dynamic generation of scenario parameters specifically includes: periodically switching the cryptographic algorithm version, protocol type, and key length based on a preset state transition model;
[0058] The state transition model includes a state space and a transition probability matrix; wherein the state space includes a set of values of the cryptographic algorithm version, protocol type, and key length; the transition probability matrix is used to calculate the transition probability of switching the current state space to any state space;
[0059] The parameter configuration unit is configured with a parameter change cycle; at the beginning of each parameter change cycle, the parameter configuration unit switches the current state space to the state space with the maximum transition probability based on the transition probability matrix, thereby realizing dynamic generation of scene parameters.
[0060] Preferably, a reinforcement learning algorithm is used to dynamically adjust the transition probability matrix, and the optimization goal of the reinforcement learning algorithm is: the difference in Kolmogorov complexity of the state space before and after switching is within a preset threshold range, so that the amplitude of the scene parameter change between adjacent state spaces is constrained by a preset teaching difficulty threshold.
[0061] The image generation unit generates a simulation application image based on the scenario parameters, specifically including:
[0062] Load a preset container build template; inject the current cryptographic algorithm version, protocol type, and key length into the container build template to generate container build instructions; this application prefers the Dockerfile template as the container build template. Based on the container build instructions, call the container build tool to generate the simulation application image.
[0063] The vulnerability deduction module generates a vulnerability chain based on the pre-set vulnerability association knowledge graph and the scenario parameters, and encapsulates the vulnerabilities contained in the vulnerability chain into a vulnerability image and transmits it to the scenario generation module; the scenario generation module integrates the vulnerability image into the simulation application image to generate a composite image;
[0064] The vulnerability deduction module includes a knowledge graph unit, a deduction engine unit, and a vulnerability mirror unit; wherein the knowledge graph unit is configured with a vulnerability-related knowledge graph; the vulnerability-related knowledge graph includes entity nodes and relationship edges; the entity nodes include vulnerability nodes, protocol type nodes, and cryptographic algorithm nodes; the relationship edges include reachability edges, protocol dependency edges, and algorithm weakening edges;
[0065] Vulnerability nodes are connected by reachability edges, which represent the potential for lateral movement of vulnerability exploits—that is, the likelihood of chained triggering between vulnerabilities. Connecting vulnerability nodes via reachability edges ensures that vulnerability chains conform to the lateral movement patterns of real-world penetration testing. Vulnerabilities are selected and added to the CVE vulnerability library, and each vulnerability node is assigned a unique number using the CVE identification number.
[0066] The vulnerability node and the protocol type node are connected by a protocol dependency edge; the protocol dependency edge is used to identify the protocol environment required for the vulnerability to be triggered; the vulnerability node and the cryptographic algorithm node are connected by an algorithm weakening edge; the algorithm weakening edge is used to associate the algorithm defect with the cause of the vulnerability; for example, the RSA algorithm and the RSA short key derivation vulnerability are connected by an algorithm weakening edge.
[0067] The deduction engine unit is used to generate a vulnerability chain, specifically including:
[0068] Parse the current scenario parameters and read the current cryptographic algorithm version, protocol type, and key length;
[0069] Prune the vulnerability-related knowledge graph based on the current cryptographic algorithm version, protocol type, and key length to obtain the vulnerability chain;
[0070] The vulnerability nodes in the vulnerability chain are encapsulated into vulnerability images that can be started and stopped independently, and the network service port mapping relationship is retained between the vulnerability images corresponding to adjacent vulnerability nodes.
[0071] By retaining the network service port mapping relationship between adjacent vulnerabilities in the vulnerability chain, the triggering order of the vulnerabilities in the vulnerability chain can be preserved, chain encapsulation of vulnerability images can be achieved, and service dependencies between vulnerability images can be ensured (for example, any vulnerability needs to access any port of an adjacent vulnerability).
[0072] The pruning of the vulnerability-related knowledge graph specifically includes:
[0073] Filter cryptographic algorithm nodes based on the cryptographic algorithm version; mark cryptographic algorithm nodes that do not conform to the current cryptographic algorithm version as illegal nodes;
[0074] Filter protocol type nodes based on protocol type; mark protocol type nodes that do not conform to the current protocol type as illegal nodes;
[0075] Remove vulnerability nodes connected to illegal nodes in the vulnerability association knowledge graph.
[0076] By screening the cryptographic algorithm version and protocol type, the vulnerability-related knowledge graph is dynamically pruned, achieving hard condition matching between scenario parameters and vulnerability chains.
[0077] Based on the key length, a weight value is assigned to the algorithm weakening edge of each vulnerability node in the vulnerability association knowledge graph; specifically, the weight mapping table between key length and cryptographic algorithm type is preset; based on the weight mapping table, the weight of each cryptographic algorithm type under the current key length is queried; based on the weight of the cryptographic algorithm type corresponding to the cryptographic algorithm node connected to the vulnerability node, a weight value is assigned to the algorithm weakening edge;
[0078] A weight threshold interval is preset; vulnerability nodes connected by algorithm-weakened edges whose weight values are not within the weight threshold interval are removed from the vulnerability-related knowledge graph.
[0079] The weight mapping table specifies the weight of each cryptographic algorithm type, which quantifies the security of each algorithm under the current key length, i.e., the difficulty of cracking it. The weight is negatively correlated with the algorithm's cracking difficulty: a higher weight indicates a lower cracking difficulty and a higher probability of triggering the corresponding vulnerability. For example, if the ECC algorithm is more secure than the RSA algorithm under the same key length, the weight of the algorithm-weakening edge corresponding to the ECC algorithm will be lower than that of the algorithm-weakening edge corresponding to the RSA algorithm. This quantifies the key length into a mathematical constraint, enabling soft-constraint screening of vulnerable nodes.
[0080] Preferably, the weight of the algorithm-weakening edge is modified based on the cryptographic algorithm version. For example, if the cryptographic algorithm version is OpenSSL 1.1.1 or earlier, the weight of the algorithm-weakening edge corresponding to the RSA algorithm is increased; if the cryptographic algorithm version is OpenSSL 3.0 or later, the weight of the algorithm-weakening edge corresponding to the RSA algorithm is decreased. Due to the side-channel vulnerability in OpenSSL versions below 1.1.1, the probability of triggering the vulnerability involving the RSA algorithm is higher. However, OpenSSL 3.0 or later uses default padding protection, making the vulnerability more difficult to trigger.
[0081] The vulnerability image unit is used to encapsulate the vulnerability image and transmit the vulnerability image to the image generation unit; the image generation unit integrates the vulnerability image into the simulation application image to generate a composite image, specifically including: merging the vulnerability image and the simulation application image in layers to generate a composite image that includes the triggering environment of each vulnerability image. For example, using the UnionFS (union file system) mechanism of the Docker image, the vulnerability image is merged with the simulation application image in the form of an independent layer, and the cryptographic library carried by the vulnerability image layer and the cryptographic library of the simulation application image form a parallel library and coexist. When the composite image is started, the entry script is executed, and the service configuration carried by the vulnerability image layer is selectively enabled according to the scenario parameters, such as the weak encryption suite configuration.
[0082] The basic service module deploys a network environment based on the network requirements of the vulnerability chain and binds the composite image to the network environment to form a scenario instance;
[0083] The basic service module includes a network configuration unit and a cryptographic service unit. The network configuration unit deploys a network environment based on the vulnerability chain's network requirements. These requirements include a protocol communication matrix, topology constraints for triggering vulnerabilities in the vulnerability chain, and access control rules for the vulnerabilities in the vulnerability chain. For example, topology constraints include the minimum number of network hops and the maximum transmission delay threshold between vulnerability images. Access control rules include unidirectional connectivity constraints between vulnerability images, simulating firewall policies in real networks. The protocol communication matrix is used to record the network protocol type and port number range required to trigger each vulnerability in the vulnerability chain.
[0084] The network configuration unit deploys a network environment based on the network requirements of the vulnerability chain, specifically including:
[0085] Parse the protocol communication matrix of the vulnerability chain and generate a virtual network topology; the virtual network topology has at least one demilitarized zone (DMZ) and two isolated private subnets;
[0086] Based on the topology constraints, the OSPF weight parameters of the software-defined router are configured in the virtual network to ensure that the actual number of network hops and transmission delay between any two vulnerable images meet the preset thresholds;
[0087] Based on the access control rules, a one-way communication tunnel is established between the vulnerability images. The present application preferably uses the Netfilter / iptables tool chain to implement the access control rules and complete the establishment of a one-way communication tunnel between the vulnerability images.
[0088] The network configuration unit is further configured to bind the composite image to the network environment to form a scenario instance. The preferred method of binding the composite image to the network environment to form a scenario instance in this application includes:
[0089] Allocate a virtual network interface card (vNIC) to each composite image and associate it with a designated virtual switch port;
[0090] Establishing port mapping rules based on the protocol communication matrix to dynamically map the physical port of the host machine to the trigger port of the vulnerability image in the composite image;
[0091] Inject environment variables into the composite image, where the environment variables include the IP-CIDR format network address and routing table information of the vulnerable image.
[0092] The scenario instances are used to provide a dynamically evolving cryptographic attack and defense training environment. Each scenario instance contains at least three logically isolated attack surfaces: the protocol handshake negotiation surface, the key exchange surface, and the data transmission encryption surface. The scenario instances support multi-node coordinated attack simulations and allow the network access rights of subsequent nodes to be dynamically activated by the vulnerability trigger status of the predecessor node in the vulnerability chain.
[0093] The cryptographic service unit is used to connect to the hardware encryption device and provide an encryption algorithm interface for the simulated application image. The image generation unit encapsulates the simulated application image using tools such as Docker and deploys the encryption algorithm interface in the image. When the simulated application image runs in a scenario instance, the encryption algorithm interface is loaded and the hardware encryption device is called, ensuring that the simulated application image can call the same cryptographic service as the real business.
[0094] The feedback control module is used to monitor the trigger state parameters of the vulnerability image; the feedback control module also drives the adjustment of the scenario parameters based on the trigger state parameters, and drives the update of the vulnerability chain based on the adjustment of the scenario parameters.
[0095] The feedback control module includes a vulnerability monitoring unit and a control instruction unit; wherein, the vulnerability monitoring unit is used to monitor the trigger status parameters of the vulnerability image; the trigger status parameters include the trigger identifier of the vulnerability image; the trigger identifier of the vulnerability image is used to mark whether the corresponding vulnerability image is successfully triggered; this application determines whether the corresponding vulnerability image is successfully triggered by recording whether the vulnerability exploitation payload is successfully executed.
[0096] The control instruction unit drives the adjustment of the scene parameters based on the trigger state parameters, specifically including:
[0097] The triggering success rate of the vulnerability image and the number of vulnerability triggering times are calculated based on the triggering identifier of the vulnerability image; the switching frequency of the cryptographic algorithm version is adjusted based on the triggering success rate of the vulnerability image; and the key length is adjusted based on the number of vulnerability triggering times.
[0098] The present application preferably adjusts the frequency of switching cryptographic algorithm versions based on the trigger success rate as follows: when the trigger success rate exceeds a preset success rate threshold, the cryptographic algorithm version is switched during each parameter change cycle; otherwise, the cryptographic algorithm version is switched once every m parameter change cycles. m is a positive integer. Furthermore, the present application also preferably adjusts the key length based on the number of vulnerability triggers as follows: when the number of vulnerability triggers exceeds a preset trigger threshold, the key length is increased to the next security level, for example, increasing the key length from 2048 bits to 3072 bits.
[0099] The control instruction unit also drives the update of the vulnerability chain based on the adjustment of the scenario parameters, specifically including:
[0100] The control instruction unit sends an update instruction to the deduction engine unit; the deduction engine unit responds to the update instruction, parses the current scenario parameters and generates a new vulnerability chain; the vulnerability mirror unit encapsulates the newly added vulnerability image based on the new vulnerability chain; the scenario generation module injects the newly added vulnerability image into the running scenario instance and migrates the historical status data of the triggered vulnerability image to the newly added vulnerability image.
[0101] The historical status data of triggered vulnerability images includes the number of the triggered vulnerability and the triggering timestamp sequence, the hash value of the attack payload, and the path of the remaining temporary file. By migrating this data, we ensure that newly added vulnerability chain nodes can inherit the attack chain context (such as reusing SSH session keys for lateral movement), achieving continuous simulation of real APT attacks and avoiding the sense of disconnection in the training environment caused by vulnerability chain updates. By injecting the newly added vulnerability images into the running scenario instance, we achieve hot replacement of the vulnerability images, ensuring the continuity of password training.
[0102] Example 2
[0103] This embodiment is the second embodiment of the present application; it is based on the same inventive concept as embodiment 1, and Figure 2 This embodiment introduces a method for generating a dynamically evolving cryptographic training scenario, including the following steps:
[0104] Based on the preset state transition model, the scenario parameters are dynamically generated; the cryptographic algorithm version, protocol type, and key length are periodically switched through the preset state transition model to achieve dynamic generation of scenario parameters.
[0105] Based on the scenario parameters, a simulation application image is generated; a preset container construction template is loaded, the scenario parameters are injected to generate a container construction instruction, and a container construction tool is called to generate the simulation application image.
[0106] A vulnerability image is generated based on the scenario parameters and a preset vulnerability association knowledge graph; the preset vulnerability association knowledge graph is pruned according to the scenario parameters to obtain a vulnerability chain, and the vulnerability nodes in the vulnerability chain are encapsulated into a vulnerability image.
[0107] Generate a composite image based on the simulated application image and the vulnerable image; integrate the vulnerable image into the simulated application image, and use the UnionFS mechanism such as the Docker image to perform layered merging to generate a composite image that includes the vulnerable image triggering environment.
[0108] Deploy a network environment and bind the composite image to the network environment to form a scenario instance; deploy the network environment according to the vulnerability chain network requirements, including parsing the protocol communication matrix to generate a virtual network topology, configuring router parameters, establishing a one-way communication tunnel, etc., and then bind the composite image to the network environment, assign a virtual network interface card to it, establish port mapping rules and inject environment variables to form a scenario instance that includes multiple attack surfaces and supports multi-node collaborative attack simulation.
[0109] Monitor the trigger status parameters of the vulnerability image; based on these trigger status parameters, drive the adjustment of scenario parameters and the update of the vulnerability chain. For example, adjust the frequency of switching cryptographic algorithm versions based on the trigger success rate, adjust the key length based on the number of triggers, and then drive the update of the vulnerability chain.
[0110] The specific functions of the above steps are realized by referring to the relevant contents of the dynamically evolving cryptographic training range system described in Example 1 and will not be elaborated on here.
[0111] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0112] The above describes the embodiments of the present application in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose and scope of protection of this application, all of which are protected by this application.
Claims
1. A dynamically evolving cryptography training range system, characterized by: It includes scenario generation module, vulnerability deduction module, basic service module, and feedback control module; among them: The scenario generation module is used to dynamically generate scenario parameters and generate a simulation application image based on the scenario parameters; The scenario generation module includes a parameter configuration unit; the parameter configuration unit is used to dynamically generate scenario parameters; the scenario parameters include a cryptographic algorithm version, a protocol type, and a key length; the dynamic generation of scenario parameters specifically includes: periodically switching the cryptographic algorithm version, protocol type, and key length based on a preset state transition model; The state transition model includes a state space and a transition probability matrix; wherein the state space includes a set of values of the cryptographic algorithm version, protocol type, and key length; the transition probability matrix is used to calculate the transition probability of switching the current state space to any state space; The parameter configuration unit is configured with a parameter change cycle; at the beginning of each parameter change cycle, the parameter configuration unit switches the current state space to the state space with the maximum transition probability based on the transition probability matrix, thereby dynamically generating scene parameters; The vulnerability deduction module generates a vulnerability chain based on the pre-set vulnerability association knowledge graph and the scenario parameters, and encapsulates the vulnerabilities contained in the vulnerability chain into a vulnerability image and transmits it to the scenario generation module; the scenario generation module integrates the vulnerability image into the simulation application image to generate a composite image; The basic service module deploys a network environment based on the network requirements of the vulnerability chain and binds the composite image to the network environment to form a scenario instance; The feedback control module is used to monitor the trigger state parameters of the vulnerability image; the feedback control module also drives the adjustment of the scenario parameters based on the trigger state parameters, and drives the update of the vulnerability chain based on the adjustment of the scenario parameters.
2. The dynamically evolving cryptography training range system according to claim 1, characterized in that: The scene generation module also includes a mirror generation unit; The image generation unit generates a simulation application image based on the scenario parameters, specifically including: Load the preset container construction template; inject the current cryptographic algorithm version, protocol type, and key length into the container construction template to generate a container construction instruction; call the container construction tool based on the container construction instruction to generate a simulation application image.
3. The dynamically evolving cryptography training range system according to claim 2, wherein: The vulnerability deduction module includes a knowledge graph unit; the knowledge graph unit is configured with a vulnerability-related knowledge graph; the vulnerability-related knowledge graph includes entity nodes and relationship edges; the entity nodes include vulnerability nodes, protocol type nodes, and cryptographic algorithm nodes; the relationship edges include reachability edges, protocol dependency edges, and algorithm weakening edges; The vulnerability nodes are connected by the reachability edge; the reachability edge is used to indicate the possibility of lateral movement of vulnerability exploitation; the vulnerability node and the protocol type node are connected by the protocol dependency edge; the protocol dependency edge is used to identify the protocol environment required for vulnerability triggering; the vulnerability node and the cryptographic algorithm node are connected by the algorithm weakening edge; the algorithm weakening edge is used to associate the algorithm defect with the cause of the vulnerability.
4. The dynamically evolving cryptography training range system according to claim 3, characterized in that: The vulnerability deduction module also includes a deduction engine unit; the deduction engine unit is used to generate a vulnerability chain, specifically including: Parse the current scenario parameters and read the current cryptographic algorithm version, protocol type, and key length; Prune the vulnerability-related knowledge graph based on the current cryptographic algorithm version, protocol type, and key length to obtain the vulnerability chain; The vulnerability nodes in the vulnerability chain are encapsulated into vulnerability images that can be started and stopped independently, and the network service port mapping relationship is retained between the vulnerability images corresponding to adjacent vulnerability nodes.
5. The dynamically evolving cryptography training range system according to claim 4, characterized in that: The pruning of the vulnerability-related knowledge graph specifically includes: Filter cryptographic algorithm nodes based on the cryptographic algorithm version; mark cryptographic algorithm nodes that do not conform to the current cryptographic algorithm version as illegal nodes; Filter protocol type nodes based on protocol type; mark protocol type nodes that do not conform to the current protocol type as illegal nodes; Remove vulnerability nodes connected to illegal nodes in the vulnerability association knowledge graph.
6. The dynamically evolving cryptography training range system according to claim 5, characterized in that: The pruning of the vulnerability-related knowledge graph further includes: Based on the key length, a weight value is assigned to the algorithm weakening edge of each vulnerability node in the vulnerability association knowledge graph; specifically, the weight mapping table between key length and cryptographic algorithm type is preset; based on the weight mapping table, the weight of each cryptographic algorithm type under the current key length is queried; based on the weight of the cryptographic algorithm type corresponding to the cryptographic algorithm node connected to the vulnerability node, a weight value is assigned to the algorithm weakening edge; A weight threshold interval is preset; vulnerability nodes connected by algorithm-weakened edges whose weight values are not within the weight threshold interval are removed from the vulnerability-related knowledge graph.
7. The dynamically evolving cryptography training range system according to claim 6, characterized in that: The vulnerability deduction module includes a vulnerability mirror unit; The vulnerability image unit is used to encapsulate the vulnerability image and transmit the vulnerability image to the image generation unit; The image generation unit integrates the vulnerability image into the simulation application image to generate a composite image, specifically including: merging the vulnerability image and the simulation application image in layers to generate a composite image containing the triggering environment of each vulnerability image.
8. The dynamically evolving cryptography training range system according to claim 7, characterized in that: The basic service module includes a network configuration unit; the network configuration unit deploys a network environment based on the network requirements of the vulnerability chain; the network requirements of the vulnerability chain include a protocol communication matrix, topology constraints for triggering vulnerabilities in the vulnerability chain, and access control rules for vulnerabilities in the vulnerability chain; the protocol communication matrix is used to record the network protocol type and port number range required to trigger each vulnerability in the vulnerability chain; The network configuration unit is further used to bind the composite image to the network environment to form a scenario instance.
9. The dynamically evolving cryptography training range system according to claim 8, characterized in that: The feedback control module includes a vulnerability monitoring unit and a control instruction unit; wherein the vulnerability monitoring unit is used to monitor the trigger state parameters of the vulnerability image; the trigger state parameters include the trigger identifier of the vulnerability image; the trigger identifier of the vulnerability image is used to mark whether the corresponding vulnerability image is successfully triggered; The control instruction unit drives the adjustment of the scene parameters based on the trigger state parameters, specifically including: The triggering success rate of the vulnerability image and the number of vulnerability triggering times are calculated based on the triggering identifier of the vulnerability image; the switching frequency of the cryptographic algorithm version is adjusted based on the triggering success rate of the vulnerability image; and the key length is adjusted based on the number of vulnerability triggering times.
10. The dynamically evolving cryptography training range system according to claim 9, characterized in that: The control instruction unit also drives the update of the vulnerability chain based on the adjustment of the scenario parameters, specifically including: The control instruction unit sends an update instruction to the deduction engine unit; the deduction engine unit responds to the update instruction, parses the current scenario parameters and generates a new vulnerability chain; the vulnerability mirror unit encapsulates the newly added vulnerability image based on the new vulnerability chain; the scenario generation module injects the newly added vulnerability image into the running scenario instance and migrates the historical status data of the triggered vulnerability image to the newly added vulnerability image.
11. A method for generating a dynamically evolving cryptography training scenario, which is implemented based on a dynamically evolving cryptography training range system according to any one of claims 1 to 10, characterized in that: The following steps are involved: Dynamically generate scene parameters based on the preset state transition model; Based on the scenario parameters, generating a simulation application image; Generate a vulnerability image based on the scenario parameters and a preset vulnerability association knowledge graph; Generate a composite image based on the simulated application image and the vulnerability image; Deploy a network environment and bind the composite image to the network environment to form a scenario instance; Monitor trigger state parameters of the vulnerability image; and drive the adjustment of scenario parameters and the update of scenario instances based on the trigger state parameters.
Citation Information
Patent Citations
Operation method of an industrial internet commercial cryptography application training platform
CN116599770B
Network target range simulation method, device and equipment based on multiple parameters and medium
CN119402374A
Large-scale network node scene construction method and system based on network target range
CN119996079A