Security detection method and system, electronic equipment, storage medium and program product
By building a simulation network consistent with the network to be detected and performing security detection operations, the problem that the simulation test environment cannot reproduce the complexity and dynamic changes of the real network is solved, and the accuracy and reliability of the security detection results are achieved.
Patent Information
- Application Number
- CN202510524243.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-04
AI Technical Summary
The simulation testing environment of existing communication networks cannot reproduce the complexity and dynamic changes of the real network, resulting in deviations from the actual situation, affecting the effectiveness and accuracy of network security testing.
The simulation network is built based on the static information of the network to be detected, and the operating parameters of the simulation equipment are configured based on the dynamic information, so that the simulation network is consistent with the network to be detected, and the security detection operation is performed through an automated penetration testing tool to obtain accurate security detection results.
It improves the authenticity of the simulation network and the reliability and accuracy of the security detection results, ensuring that the normal business operation of the current network is not affected.
Smart Images

Figure CN120264282A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a security detection method, system, electronic device, storage medium, and program product. Background Art
[0002] With the rapid development of mobile communication networks, the network architecture has become increasingly complex, and network security issues have become more prominent. The security testing of mobile communication networks aims to comprehensively evaluate the network's ability to resist various security threats and ensure the stability of network services and the security of user data.
[0003] In order not to affect the normal operation of the existing network, the security testing of communication networks is usually not directly carried out in the existing network environment, but through building a simulation testing environment for security testing. However, since the simulation testing environment often fails to reproduce the complexity and dynamic changes of the real network, there are deviations between the test results and the actual security situation, affecting the effectiveness and accuracy of network security testing. Summary of the Invention
[0004] This application provides a security detection method, system, electronic device, storage medium, and program product for improving the accuracy of security detection results.
[0005] In a first aspect, this application provides a security detection method applied to a security detection platform, including: obtaining static information and dynamic information of a network to be detected; the static information is used to indicate devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected; based on the static information, constructing a simulation network; each simulation device in the simulation network corresponds one-to-one with each device in the network to be detected; based on the dynamic information, configuring the operating parameters of each simulation device in the simulation network; performing a security detection operation on the simulation network to obtain a security detection result; the security detection result is used to reflect the security status of the network to be detected.
[0006] This application provides a security detection method. This method can construct a simulation network based on the static information of the network to be detected and configure the operating parameters of each simulation device in the simulation network based on the dynamic information of the network to be detected, so that the simulation network can be consistent with the network state of the network to be detected and improve the authenticity of the simulation network. This method can also perform a security detection operation on the simulation network to obtain a security detection result, thereby improving the reliability and accuracy of the security detection result without affecting the normal operation of the existing network.
[0007] A possible implementation is that the security detection platform includes a virtual resource library; based on static information, a simulation communication network is constructed, including: determining a simulation test template based on the topological relationship in the static information; based on the device information in the static information, calling the virtualized resources corresponding to the device information from the virtual resource library to configure the simulation test template, and obtaining a simulation network.
[0008] Another possible implementation is that multiple detection points are deployed in the communication network, and static information and dynamic information of the network to be detected are obtained, including: obtaining a detection requirement, which is used to indicate a security detection operation for a specific scenario or a specific area of the communication network; determining one or more detection points associated with the detection requirement from the multiple detection points; and obtaining the static information and dynamic information of the network to be detected through the one or more detection points.
[0009] Another possible implementation is that based on the dynamic information, the operating parameters of each simulation device in the simulation network are configured, including: through the one or more detection points, synchronizing the operating parameters of each device in the network to be detected to the corresponding simulation devices in the simulation network.
[0010] Another possible implementation is that a security detection operation is performed on the simulation network, including: determining test cases based on one or more of the detection requirement, threat intelligence information, dynamic information, and static information; where the detection requirement is used to indicate a security detection operation for a specific scenario or a specific area of the communication network; the threat intelligence information is used to provide known vulnerability information in the communication network; and using an automated penetration testing tool to run the test cases to perform the security detection operation on the simulation network.
[0011] Another possible implementation is that the test cases are used to detect at least one of the following: malicious attack traffic, Trojan programs, and malicious files; the security test results include at least one of the following: risk locations, attack methods, attack paths, and attack traffic.
[0012] Another possible implementation is that the method further includes: when the security detection operation is completed, recycling the virtualized resources used to build the simulation network.
[0013] In a second aspect, the present application provides a security detection system, including: a security detection platform and a communication network; the communication network includes a network to be detected; one or more detection points are deployed in the network to be detected; the security detection platform is configured to obtain static information and dynamic information of the network to be detected through the one or more detection points; the static information is used to indicate devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected; based on the static information, a simulation network of the network to be detected is constructed; each simulation device in the simulation network corresponds one-to-one with each device in the network to be detected; based on the dynamic information, the operating status parameters of each simulation device in the simulation network are adjusted; a security detection operation is performed on the simulation network to obtain a security detection result; the security detection result is used to reflect the security status of the network to be detected.
[0014] In a third aspect, the present application provides a security detection device, including: an acquisition module and a processing module; the acquisition module is configured to obtain static information and dynamic information of the network to be detected; the static information is used to indicate devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected; the processing module is configured to construct a simulation network based on the static information; each simulation device in the simulation network corresponds one-to-one with each device in the network to be detected; based on the dynamic information, the operating parameters of each simulation device in the simulation network are configured; a security detection operation is performed on the simulation network to obtain a security detection result; the security detection result is used to reflect the security status of the network to be detected.
[0015] A possible implementation, the processing module is specifically configured to determine a simulation test template based on the topological relationship in the static information; based on the device information in the static information, call the virtualization resources corresponding to the device information from the virtual resource library to configure the simulation test template, and obtain a simulation network.
[0016] Another possible implementation, a plurality of detection points are deployed in the communication network, and the acquisition module is specifically configured to obtain a detection requirement, where the detection requirement is used to indicate a security detection operation for a specific scenario or a specific area of the communication network; determine one or more detection points associated with the detection requirement from the plurality of detection points; obtain the static information and dynamic information of the network to be detected through the one or more detection points.
[0017] Another possible implementation, the acquisition module is specifically configured to synchronize the operating parameters of each device in the network to be detected to the corresponding simulation device in the simulation network through the one or more detection points.
[0018] Another possible implementation, a processing module, specifically configured to determine test cases based on one or more of detection requirements, threat intelligence information, dynamic information, and static information; wherein, the detection requirements are used to indicate security detection operations for specific scenarios or specific areas of the communication network; the threat intelligence information is used to provide known vulnerability information in the communication network; an automated penetration testing tool is used to run the test cases to perform security detection operations on the simulation network.
[0019] Another possible implementation, the test cases are used to detect at least one of the following: malicious attack traffic, Trojan programs, and malicious files; the security test results include at least one of the following: risk locations, attack methods, attack paths, and attack traffic.
[0020] Another possible implementation, the processing module is further configured to recycle the virtualization resources used to build the simulation network when the security detection operation is completed.
[0021] In a fourth aspect, the present application provides an electronic device, which includes: a processor and a memory; the memory stores instructions executable by the processor; when the processor is configured to execute the instructions, the electronic device implements the method of the first aspect above.
[0022] In a fifth aspect, the present application provides a computer-readable storage medium, which includes: computer software instructions; when the computer software instructions run in an electronic device, the electronic device implements the method of the first aspect above.
[0023] In a sixth aspect, the present application provides a computer program product, which includes a computer program; when the computer program runs in an electronic device, the electronic device implements the method of the first aspect above.
[0024] For the beneficial effects of the second to sixth aspects above, refer to the corresponding descriptions of the first aspect and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 It is a schematic diagram of the system architecture of a security detection method provided by the present application;
[0026] Figure 2 It is a flowchart of a security detection method provided by the present application;
[0027] Figure 3 It is a flowchart of another security detection method provided by the present application;
[0028] Figure 4 It is a flowchart of yet another security detection method provided by the present application;
[0029] Figure 5Compositional example diagram of a security detection platform provided by this application;
[0030] Figure 6 Schematic diagram of the composition of a security detection device provided by this application;
[0031] Figure 7 Schematic diagram of the structure of an electronic device provided by this application. Detailed implementation manners
[0032] The security detection method provided by this application will be described in detail below with reference to the accompanying drawings.
[0033] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone.
[0034] The terms "first" and "second" in the description of this application and the accompanying drawings are used to distinguish different objects or different processes for the same object, rather than to describe the specific order of the objects.
[0035] In addition, the terms "including" and "having" mentioned in the description of this application and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include other unlisted steps or units, or may optionally further include other steps or units inherent to these processes, methods, products, or devices.
[0036] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly, using words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0037] To facilitate a clear description of the technical solutions of the embodiments of this application, in the embodiments of this application, words such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that the words such as "first" and "second" are not limiting the quantity and execution order.
[0038] In the description of this application, unless otherwise specified, the meaning of "a plurality of" refers to two or more.
[0039] With the rapid development of mobile communication networks, the network architecture has become increasingly complex, and network security issues have become more prominent. The security testing of mobile communication networks aims to comprehensively evaluate the network's ability to resist various security threats and ensure the stability of network services and the security of user data.
[0040] In order not to affect the normal operation of the existing network, the security testing of communication networks is usually not directly carried out in the existing network environment, but through building a simulation test environment for security testing. However, since the simulation test environment often fails to reproduce the complexity and dynamic changes of the real network, there are deviations between the test results and the actual security situation, affecting the effectiveness and accuracy of network security testing.
[0041] To address the above technical problems, this application provides a security detection method. The idea is to build a simulation network based on the static information of the network to be detected, and configure the operating parameters of each simulation device in the simulation network based on the dynamic information of the network to be detected, so that the simulation network can be consistent with the network state of the network to be detected, improving the authenticity of the simulation network. And, by performing security detection operations on the simulation network, a security detection result is obtained, thereby improving the reliability and accuracy of the security detection result without affecting the normal operation of the existing network by enhancing the authenticity of the simulation network.
[0042] The following will specifically introduce the embodiments provided by this application in conjunction with the accompanying drawings of the specification.
[0043] The security detection method provided by this application can be applied to a security detection system as Figure 1 shown. The security detection system includes: a security detection platform 110 and a communication network 120. As Figure 1 shown, the security detection platform 110 is interconnected with the communication network 120. The communication network 120 includes a network to be detected 121, and one or more detection points are deployed in the network to be detected.
[0044] Among them, the security detection platform 110 is used to obtain the static information and dynamic information of the network to be detected 121 through one or more detection points. The static information is used to indicate the devices in the network to be detected 121 and the topological relationship between the devices. The dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected 121; based on the static information, build a simulation network of the network to be detected 121, and each simulation device in the simulation network corresponds one-to-one with each device in the network to be detected; based on the dynamic information, adjust and configure the operating state parameters of each simulation device in the simulation network; perform security detection operations on the simulation network to obtain a security detection result; the security detection result is used to reflect the security status of the network to be detected 121.
[0045] In some embodiments, multiple detection points are deployed in the communication network 120. The security detection platform 110 can obtain detection requirements, which are used to indicate security detection operations for specific scenarios or specific areas of the communication network 120. The security detection platform 110 can also determine one or more detection points associated with the detection requirements from the multiple detection points. Through the one or more detection points, static information and dynamic information of the network 121 to be detected are obtained.
[0046] In some embodiments, the security detection platform 110 can be a server cluster composed of multiple servers, or a single server, or a computer, or a processor or processing chip in the server or computer, etc. The specific device form of the security detection platform 110 in the embodiments of the present application is not limited.
[0047] In some embodiments, the communication network 120 can provide necessary infrastructure for the normal business operation of the existing network. Exemplarily, the communication network 120 can include communication network infrastructure such as network elements, routers, switches, base stations, servers, terminals, gateways, network management systems (NMS), and wireless access points (WAP).
[0048] It should be noted that the system architecture described in the embodiments of the present application is for more clearly explaining the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of the system architecture, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.
[0049] See Figure 2 , which is a schematic flowchart of a security detection method provided by the embodiments of the present application. As Figure 2 shown, the security detection method provided by the present application is applied to the above security detection platform, and specifically includes the following steps S201 to S204.
[0050] S201. Obtain static information and dynamic information of the network to be detected.
[0051] Among them, the static information is used to indicate the devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected.
[0052] In some embodiments, the network devices in the network to be detected may include one or more of basic network devices such as network elements, routers, switches, base stations, servers, terminals, gateways, network management systems, wireless access points, etc. The dynamic information of the network to be detected may include one or more of device status information, device configuration information, and network traffic information.
[0053] Among them, the device status information is used to indicate the usage of the central processing unit (CPU) and memory of the device. For example, the device status information may include the CPU utilization rate of the device; the device configuration information includes configuration file information of different versions of the device and the configuration change records of the device; the network traffic information may include at least one of the following: the number of data packets sent / received by the device, the number of bytes, the change trend of the traffic, the network bandwidth utilization rate, etc.
[0054] It can be understood that since the security requirements and potential risk issues in different application scenarios and different network regions in the communication network are different, it is necessary to perform security detection on the networks in different scenarios and regions separately. The devices in the network to be detected and the topological relationship between the devices in a specific scenario and region are relatively fixed, but the device status information, device configuration information, and traffic information may change frequently.
[0055] Based on this, the devices in the network to be detected and the topological relationship between the devices can be regarded as the static information of the network to be detected. The structural layout of the devices in the network to be detected can be clarified through the devices in the network to be detected and the topological relationship between the devices; the device status information, device configuration information, and traffic information in the network to be detected can also be regarded as the dynamic information of the network to be detected. The actual operating status of the network to be detected can be clarified through the device status information, device configuration information, and traffic information in the network to be detected.
[0056] S202. Construct a simulation network based on the static information; each simulation device in the simulation network corresponds to each device in the network to be detected one by one.
[0057] It can be understood that by constructing a virtualized simulation network for network security detection, the impact of network security detection on the real network can be effectively avoided. In order to ensure that the simulation environment reflects the state and behavior of the real network as realistically as possible, each simulation device in the simulation network corresponds to each device in the network to be detected one by one.
[0058] In some embodiments, the simulation devices in the simulation network include at least one of the following: virtual network elements, virtual routers, virtual switches, virtual base stations, virtual servers, virtual terminals, virtual gateways, virtual network management systems.
[0059] In some embodiments, the security detection platform includes a virtual resource library, which includes virtual resources for constructing various simulation devices. Since the static information of the network to be detected can reflect the structural layout of the devices in the network to be detected, the static information of the network to be detected can be used to call the virtual resources in the virtual resource library and generate a simulation network with the assistance of templates, thereby improving the speed and efficiency of constructing the simulation network.
[0060] Exemplarily, as Figure 3 shown, the above S202 can be implemented as the following steps S2021 - S2022.
[0061] S2021. Determine a simulation test template based on the topological relationship in the static information.
[0062] In some embodiments, the topological relationship in the static information can be converted into the connection rules between the simulation devices in the simulation test template, such as the interface binding relationship and link attributes between each simulation device, so as to create a simulation test template.
[0063] S2022. Based on the device information in the static information, call the virtual resources corresponding to the device information from the virtual resource library to configure the simulation test template, and obtain a simulation network.
[0064] In some embodiments, based on the device information in the static information, suitable virtual resources can be matched for different devices, such as routers, switches, servers, etc., and then the simulation test template can be called and configured to obtain a simulation network.
[0065] S203. Configure the running parameters of each simulation device in the simulation network based on the dynamic information.
[0066] It can be understood that since the dynamic information of the network to be detected can reflect the actual running state of the network to be detected, therefore, based on the dynamic information, configuring the running parameters of each simulation device in the simulation network can improve the consistency and real-time performance between the simulation network and the network to be detected. Furthermore, the accuracy of the security detection results can be improved through the security detection of the highly restored simulation network.
[0067] In some embodiments, one or more detection points are set in the network to be detected, and the security detection platform can obtain the running parameters of each device in the network to be detected through the one or more detection points set in the network to be detected. Therefore, the above step S203 can be implemented as: synchronize the running parameters of each device in the network to be detected to the corresponding simulation devices in the simulation network through the one or more detection points.
[0068] Among them, the running parameters of each device can include at least one of the following: interface traffic, link status, device configuration information.
[0069] Exemplarily, the operating parameters of the device can be synchronized to the configuration file of the corresponding simulation device in the simulation network. Then, by reloading the configuration of the simulation device, the operating parameters of each device in the network to be detected can be synchronized to the corresponding simulation device in the simulation network. The interface traffic of each device in the network to be detected can also be simulated by a traffic simulator in the simulation network, so as to synchronize the interface traffic of each device to the corresponding simulation device in the simulation network.
[0070] It should be noted that the detection point is a hardware device, software tool or virtualization component deployed in the network to be detected for collecting dynamic information and static information of the network to be detected. Exemplarily, the detection point can be a dedicated network probe, sensor, simple network management protocol (SNMP) agent, log collector, traffic analysis tool or virtual machine, etc.
[0071] S204. Perform a security detection operation on the simulation network to obtain a security detection result.
[0072] The security detection result is used to reflect the security status of the network to be detected.
[0073] In some embodiments, when performing the security detection operation, test cases can be used to simulate specific attack behaviors on the simulation network to detect whether there are security vulnerabilities in the simulation network. Therefore, an automated penetration testing tool and test cases can be used to perform the security detection operation on the simulation network to improve the efficiency and accuracy of the security detection. Based on this, performing the security detection operation on the simulation network can include the following steps A1 - A2.
[0074] A1. Determine test cases based on one or more of the detection requirements, threat intelligence information, dynamic information, and static information.
[0075] The detection requirements are used to indicate performing a security detection operation on a specific scenario or specific area of the communication network; the threat intelligence information is used to provide known vulnerability information in the communication network.
[0076] It is understandable that the detection requirements, dynamic information, and static information can help the security detection platform identify the functional logic, user behavior, and potential risk points of the network to be detected; threat intelligence information can help the security detection platform obtain known vulnerability information in the communication network, such as malicious Internet Protocol (IP) addresses and domain names, file hashes of known malware, specific malware signatures or Uniform Resource Locators (URLs), abnormal network traffic patterns, etc. Therefore, determining test cases based on one or more of the detection requirements, threat intelligence information, dynamic information, and static information can enhance the pertinence and coverage of security detection operations, thereby improving the accuracy of security detection results.
[0077] In some embodiments, the security detection platform can be connected to a threat intelligence sharing center to obtain the latest threat intelligence information in real time, so that security test cases can detect the simulation network based on the latest attack patterns and vulnerabilities, improving the timeliness of the test cases. Among them, the threat intelligence sharing center can include one or more of industry-specific Information Sharing and Analysis Centers (ISACs), Malware Information Sharing Platform (MISP), Common Vulnerabilities and Exposures (CVE) database, vulnerability reward program reports, advanced persistent threat (APT) organization analysis, and Known Exploited Vulnerabilities (KEV) catalog.
[0078] A2. Run the test cases using an automated penetration testing tool to perform security detection operations on the simulation network.
[0079] In some embodiments, the test cases are used to detect at least one of the following: malicious attack traffic, Trojan programs, and malicious files.
[0080] Exemplarily, in the case where the test case is used to detect malicious attack traffic, the automated penetration testing tool can, based on the indication of the test case, simulate the attack traffic and launch an attack on the emulated network, so as to detect whether the emulated network can accurately identify and block the malicious attack traffic; in the case where the test case is used to detect Trojan programs, the automated penetration testing tool can also, based on the indication of the test case, deploy known Trojan programs into the emulated network, and by monitoring the behavior of the Trojans, detect whether the emulated network can detect and isolate the Trojan programs; in the case where the test case is used to detect malicious files, the automated testing tool can also, based on the indication of the test case, deploy malicious files embedded with malicious scripts or carrying viruses into the emulated network, and detect whether the emulated network can intercept the download, transmission, or execution of the malicious files.
[0081] In some embodiments, one or more detection points are set in the emulated network for collecting at least one of traffic information, behavior information, performance information, and attack verification information of the emulated network. The security detection platform can obtain the information collected by the detection points and determine the security test result based on one or more of the traffic information, behavior information, performance information, and attack verification information. Among them, the security detection result is used to reflect the security status of the network to be detected.
[0082] It should be noted that the traffic information refers to the relevant information of the data packets or data streams transmitted in the emulated network. Based on the analysis of the traffic information in the emulated network, the security detection platform can identify the abnormal activities and malicious traffic in the emulated network.
[0083] The behavior information includes the abnormal operations and interaction patterns of each emulated device and / or application in the emulated network. Based on the analysis of the behavior information in the emulated network, the security detection platform can identify the behavior characteristics of Trojan programs or other malicious software in the emulated network.
[0084] The performance information reflects the operating status of the emulated network. Based on the analysis of the performance information in the emulated network, the security detection platform can troubleshoot the vulnerabilities and faults that will affect the network performance in the emulated network.
[0085] The attack verification information is a detailed record of known or suspected attack activities. Based on the analysis of the attack verification information in the emulated network, the security detection platform can confirm the existence, scope of influence, and success or failure of the attack.
[0086] Since the emulated network can highly reproduce the network to be detected, based on the analysis of one or more of the traffic information, behavior information, performance information, and attack verification information of the emulated network, the security status of the network to be detected can be obtained.
[0087] Exemplarily, the security test results may include at least one of the following: risk location, attack method, attack path, and attack traffic. Among them, the risk location is used to indicate the specific location of vulnerabilities or weaknesses existing in the network to be detected; the attack method is used to indicate the specific attack means and techniques that can pose a threat to the network security of the network to be detected; the attack path is used to indicate the sequence of nodes and steps through which the attack that can pose a threat to the network security of the network to be detected passes, reflecting the link of vulnerability exploitation and the trajectory of lateral movement; the attack traffic is used to indicate the malicious network communication data generated during the intrusion of the network to be detected, including request content, protocol characteristics, packet payload, etc.
[0088] As can be seen from the above steps S201 - S204, the security detection method provided by this application can construct a simulation network based on the static information of the network to be detected and configure the operating parameters of each simulation device in the simulation network based on the dynamic information of the network to be detected, so that the simulation network can be consistent with the network state of the network to be detected, improving the authenticity of the simulation network. This method can also obtain security detection results by performing security detection operations on the simulation network, thereby improving the reliability and accuracy of the security detection results without affecting the normal business operation of the existing network by improving the authenticity of the simulation network.
[0089] In some embodiments, multiple detection points are set in the communication network, and the detection points are used to monitor the operating state of the communication network and obtain the network environment information in the communication network. Since the network to be detected is a part of the communication network, the static information and dynamic information of the network to be detected can be obtained through the detection points. Exemplarily, as Figure 4 shown, the above step S201 can be implemented as the following steps S2011 - 2013.
[0090] S2011. Obtain the detection requirements, where the detection requirements are used to indicate the security detection operation for a specific scenario or specific area of the communication network.
[0091] It can be understood that since the security requirements and possible risk issues of the network to be detected are different in different scenarios, it is necessary to clarify the scenario of the network to be detected. At the same time, in order to ensure that the security detection is carried out for the network to be detected in the communication network, it is also necessary to clarify the network area and boundary range of the network to be detected. Based on this, the specific scenario or specific area of the communication network that needs to perform the security detection operation can be clarified by obtaining the detection requirements.
[0092] Exemplarily, specific scenarios of a communication network may include different application scenarios, such as user authentication and authorization, information transmission, device management, encrypted calls, cloud services, emergency response and disaster recovery, etc.; a specific area of the communication network may be a network area obtained by dividing the communication network based on geographical location, logical segmentation, functional characteristics, etc. For example, a specific area of the communication network may include a core network, an access network, a data center, a border gateway, an enterprise network, etc.
[0093] S2012. Determine one or more detection points associated with the detection requirement from multiple detection points.
[0094] Since it is necessary to perform security detection operations on a specific scenario or a specific area of the communication network, that is, only need to perform security detection operations on the network to be detected in the communication network. Therefore, screening out one or more detection points associated with the detection requirement from multiple detection points can ensure that the security detection platform can obtain the static information and dynamic information of the network to be detected from the screened detection points.
[0095] In some embodiments, in order to accurately determine one or more detection points associated with the detection requirement from multiple detection points, a detection point feature quantization evaluation system may be established to evaluate the features of each detection point, and based on the comparison between the features of the detection point and the detection requirement, determine one or more detection points associated with the detection requirement.
[0096] Exemplarily, in the case where the detection requirement is used to indicate that a specific area of the communication network performs a security detection operation, and the specific area of the communication network is a network area obtained by dividing the communication network based on geographical location, a detection point feature quantization evaluation system may be established based on the spatial correlation index of the detection point, such as topological distance weight or physical location correlation degree, etc., to evaluate the spatial distribution feature of the detection point, and based on the comparison between the spatial distribution feature of the detection point and the detection requirement, determine one or more detection points associated with the detection requirement from multiple detection points.
[0097] S2013. Obtain the static information and dynamic information of the network to be detected through one or more detection points.
[0098] In some embodiments, multiple detection points are deployed on different nodes of the communication network. For example, the detection points can be deployed in nodes such as routers, switches, firewalls, wireless access points, etc., and the detection points can also be deployed in key terminal devices in the communication network.
[0099] Among them, the detection points deployed in the router can monitor the traffic received and sent by each subnet, and can also monitor the forwarding path of data packets in the communication network; the detection points deployed in the switch can monitor the changing trend of the traffic within the local area network; the detection points deployed in the firewall can detect the access permissions between the internal and external networks, and can also monitor the intrusion behavior of abnormal traffic.
[0100] In some embodiments, the detection points deployed on the node can obtain the static information and / or dynamic information of the network to be detected by sending request information to the node. Alternatively, the node can actively send information to the detection points deployed on the node, so that the detection points can obtain the static information and / or dynamic information of the network to be detected. Further, one or more detection points send the obtained static information and dynamic information of the network to be detected to the security detection platform.
[0101] Exemplarily, the detection points deployed on the node can regularly send simple network management protocol (SNMP) request information to the device to obtain the dynamic information of the network to be detected. In the case of certain predetermined events, the node can also actively send Trap messages to the detection points based on the Trap mechanism, where the predetermined events can be events such as interface disconnection or interface connection.
[0102] In some embodiments, in order to improve the resource utilization rate of the security detection platform and reduce the operating cost, after the security detection operation is completed, the security detection platform can also recycle the virtualization resources used to build the simulation network.
[0103] Exemplarily, a task completion flag can be set in the security detection operation, and the task completion flag is used to indicate the completion status of the security detection. When the security detection platform monitors that the task completion flag indicates that the security detection operation has been completed, it can trigger the resource recycling process by calling the application programming interface (API). Among them, the resource recycling process can include deleting each simulation device instance in the simulation network and releasing the IP addresses, routing tables, etc. used when building the simulation network.
[0104] In some embodiments, the present application also provides a security detection platform. The security detection platform is used to implement the security detection method in the above method embodiments. As Figure 5As shown in the figure, it is a composition example diagram of the security detection platform provided by the embodiment of the present application. The security detection platform includes an engine, a virtual resource library, an automated penetration testing tool, and a simulation network. Among them, the security detection platform is used to construct a simulation network of the network to be detected in the communication network and perform security detection operations on the simulation network. The security detection platform is also connected to the threat intelligence sharing center to obtain threat intelligence information from the threat intelligence sharing center.
[0105] The components of the communication network include network elements, servers, virtual machines, data communication devices, gateways, base stations, network management systems, etc. At least one agent (probe point) is deployed in the communication network, and the agent is used to collect dynamic information and static information in the communication network.
[0106] The engine is the core part of the security detection platform, responsible for data analysis and task assignment in the security detection platform, and also responsible for coordinating the collaborative work of each part.
[0107] Exemplarily, the engine can obtain detection requirements, which are used to indicate security detection operations on specific scenarios or specific areas of the communication network; determine one or more agents associated with the detection requirements from multiple agents deployed in the communication network; through one or more agents, obtain static information and dynamic information of the network to be detected. Among them, the static information is used to indicate the devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected.
[0108] The engine can also determine a simulation test template based on the topological relationship in the static information; call the virtualized resource corresponding to the device information from the virtual resource library based on the device information in the static information to configure the simulation test template, obtain a simulation network, and instruct the automated penetration testing tool to run test cases to perform security detection operations on the simulation network.
[0109] The virtual resource library is responsible for the overall management of virtual resources in the security detection platform. The virtual resource library stores virtualized resources corresponding to the devices in the communication network, such as virtual network elements, virtual routers, virtual switches, virtual base stations, virtual servers, virtual terminals, virtual gateways, virtual network management systems, etc. The virtual resource library can provide resource guarantee for the rapid construction of the simulation network.
[0110] The automated penetration testing tool is used to execute the security detection tasks issued by the engine, and detect and verify whether there are security risks and hidden dangers in the simulation network by automated means.
[0111] When simulating a network, the engine constructs a virtual test environment that highly simulates the environment to be detected based on the static information and dynamic information of the network to be detected. At least one agent, that is, a detection point, is deployed in the simulated network. Through the agents deployed in the simulated network, the engine in the security detection platform can obtain at least one of the traffic information, behavior information, performance information, and attack verification information in the simulated network, and then determine the security detection result based on at least one of the traffic information, behavior information, performance information, and attack verification information in the simulated network. The security detection result is used to reflect the security status of the network to be detected.
[0112] As can be seen, the above mainly introduces the solution provided by the embodiments of the present application from the perspective of methods. To implement the above functions, the embodiments of the present application provide the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combining the modules and algorithm steps of each example described in the embodiments disclosed herein, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0113] The embodiments of the present application can divide the functional modules of the security detection device according to the above method examples. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. Optionally, the division of modules in the embodiments of the present application is illustrative, and is only a logical functional division. There may be other division methods in actual implementation.
[0114] In some embodiments, the present application further provides a security detection device. The security detection device may include one or more functional modules for implementing the security detection method of the above method embodiments.
[0115] For example, Figure 6 is a schematic diagram of the composition of a security detection device provided by an embodiment of the present application. As Figure 6 shown, the security detection device 300 includes: an acquisition module 301 and a processing module 302.
[0116] The acquisition module 301 is used to acquire the static information and dynamic information of the network to be detected; the static information is used to indicate the devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected.
[0117] A processing module 302 is configured to construct a simulation network based on static information. Each simulation device in the simulation network corresponds one-to-one to each device in the network to be detected. Based on dynamic information, operating parameters of each simulation device in the simulation network are configured. A security detection operation is performed on the simulation network to obtain a security detection result, which is used to reflect the security status of the network to be detected.
[0118] In some embodiments, the processing module 302 is specifically configured to determine a simulation test template based on the topological relationship in the static information, and call virtualized resources corresponding to the device information from the virtual resource library based on the device information in the static information to configure the simulation test template, thereby obtaining a simulation network.
[0119] In some other embodiments, multiple detection points are deployed in the communication network. The acquisition module 301 is specifically configured to obtain a detection requirement, which is used to indicate a security detection operation for a specific scenario or a specific area of the communication network; determine one or more detection points associated with the detection requirement from the multiple detection points; and obtain the static information and dynamic information of the network to be detected through the one or more detection points.
[0120] In some other embodiments, the acquisition module 301 is specifically configured to synchronize the operating parameters of each device in the network to be detected to the corresponding simulation device in the simulation network through the one or more detection points.
[0121] In some other embodiments, the processing module 302 is specifically configured to determine test cases based on one or more of the detection requirement, threat intelligence information, dynamic information, and static information, where the detection requirement is used to indicate a security detection operation for a specific scenario or a specific area of the communication network, and the threat intelligence information is used to provide known vulnerability information in the communication network. An automated penetration testing tool is used to run the test cases to perform a security detection operation on the simulation network.
[0122] In some other embodiments, the test cases are used to detect at least one of the following: malicious attack traffic, Trojan programs, and malicious files. The security test results include at least one of the following: risk location, attack method, attack path, and attack traffic.
[0123] In some other embodiments, the processing module 302 is further configured to recycle the virtualized resources used to build the simulation network when the security detection operation is completed.
[0124] When the functions of the above integrated modules are implemented in the form of hardware, an embodiment of the present invention provides a possible structural schematic diagram of the electronic device involved in the above embodiments. As Figure 7 shown, the electronic device 400 includes a processor 402, a communication interface 403, and a bus 404. Optionally, the electronic device 400 may further include a memory 401.
[0125] The processor 402 can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 402 can be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 402 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0126] The communication interface 403 is used to connect to other devices through a communication network. The communication network can be an Ethernet, a wireless access network, a wireless local area network (WLAN), etc.
[0127] The memory 401 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), or other types of dynamic storage devices that can store information and instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium, or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0128] As a possible implementation, the memory 401 can exist independently of the processor 402. The memory 401 can be connected to the processor 402 through the bus 404 and is used to store instructions or program code. When the processor 402 calls and executes the instructions or program code stored in the memory 401, the security detection method provided by the embodiments of the present invention can be implemented.
[0129] In another possible implementation, the memory 401 can also be integrated with the processor 402.
[0130] The bus 404 can be an extended industry standard architecture (EISA) bus, etc. The bus 404 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7It is represented by only one thick line, but it does not mean that there is only one bus or one type of bus.
[0131] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and conciseness of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the service call device is divided into different functional modules to complete all or part of the functions described above.
[0132] The embodiment of the present application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be instructed by computer instructions to complete the relevant hardware. This program can be stored in the above computer-readable storage medium. When this program is executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be the memory in any of the foregoing embodiments. The above computer-readable storage medium can also be an external storage device of the above service call device, such as a plug-in hard disk equipped on the above service call device, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. Further, the above computer-readable storage medium can also include both the internal storage unit of the above service call device and the external storage device. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above service call device. The above computer-readable storage medium can also be used to temporarily store the data that has been output or will be output.
[0133] The embodiment of the present application also provides a computer program product. The computer product includes a computer program. When the computer program product runs on a computer, the computer is enabled to execute any one of the security detection methods provided in the above embodiments.
[0134] The above is only the specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A security detection method, characterized in that, Applied to a security detection platform, the method includes: Obtain static information and dynamic information of the network to be detected; the static information is used to indicate the devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected; Based on the static information, construct a simulation network; each simulation device in the simulation network corresponds one-to-one with each device in the network to be detected; Based on the dynamic information, configure the operating parameters of each simulation device in the simulation network; Perform a security detection operation on the simulation network to obtain a security detection result; the security detection result is used to reflect the security status of the network to be detected.
2. The method according to claim 1, characterized in that The security detection platform includes a virtual resource library; the constructing a simulation communication network based on the static information includes: Determine a simulation test template based on the topological relationship in the static information; Based on the device information in the static information, call the virtualized resources corresponding to the device information from the virtual resource library to configure the simulation test template to obtain the simulation network.
3. The method according to claim 1, characterized in that, There are multiple detection points deployed in the communication network, and the obtaining the static information and dynamic information of the network to be detected includes: Obtain a detection requirement, which is used to indicate a security detection operation for a specific scenario or specific area of the communication network; Determine one or more detection points associated with the detection requirement from the multiple detection points; Through the one or more detection points, obtain the static information and dynamic information of the network to be detected.
4. The method according to claim 3, wherein The configuring the operating parameters of each simulation device in the simulation network based on the dynamic information includes: Through the one or more detection points, synchronize the operating parameters of each device in the network to be detected to the corresponding simulation device in the simulation network.
5. The method according to claim 1, wherein The performing a security detection operation on the simulation network includes: Determine test cases based on one or more of the detection requirement, threat intelligence information, dynamic information, and static information; wherein, the detection requirement is used to indicate a security detection operation for a specific scenario or specific area of the communication network; the threat intelligence information is used to provide known vulnerability information in the communication network; Use an automated penetration testing tool to run the test cases to perform a security detection operation on the simulation network.
6. The method according to claim 5, characterized in that, The test cases are used to detect at least one of the following: malicious attack traffic, Trojan programs, and malicious files; The security test results include at least one of the following: risk location, attack method, attack path, and attack traffic.
7. The method according to claim 2, characterized in that, The method further includes: When the security detection operation is completed, recycle the virtualized resources used to build the simulation network.
8. A security detection system, characterized in that, The system includes: a security detection platform, a communication network; the communication network includes a network to be detected; one or more detection points are deployed in the network to be detected; The security detection platform is used to obtain the static information and dynamic information of the network to be detected through the one or more detection points; the static information is used to indicate the devices in the network to be detected and the topological relationship between the devices; the dynamic information is used to indicate the current configuration and operating status of each device in the network to be detected. Based on the static information, a simulation network of the network to be detected is constructed; each simulation device in the simulation network corresponds to each device in the network to be detected one by one. Based on the dynamic information, the operating state parameters of each simulation device in the simulation network are adjusted and configured. A security detection operation is performed on the simulation network to obtain a security detection result; the security detection result is used to reflect the security status of the network to be detected.
9. An electronic device, characterized in that, It includes a processor and a memory, and the processor is coupled to the memory; the memory is used to store computer instructions, and the computer instructions are loaded and executed by the processor to enable the computer device to implement the security detection method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions, and when the computer-executable instructions run on a computer, the computer is enabled to execute the security detection method according to any one of claims 1 to 7.
11. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program runs on an electronic device, the electronic device is enabled to execute the security detection method according to any one of claims 1 to 7.